Skip to content

RFC: AI Security Bug Reporting Policy - #54

Open
makubacki wants to merge 1 commit into
OpenDevicePartnership:mainfrom
makubacki:update_security_policy_for_ai
Open

RFC: AI Security Bug Reporting Policy#54
makubacki wants to merge 1 commit into
OpenDevicePartnership:mainfrom
makubacki:update_security_policy_for_ai

Conversation

@makubacki

Copy link
Copy Markdown
Contributor

Updates the ODP security policy to account for security bugs found using AI tools to make handling such findings consistent and efficient across the organization.

@makubacki makubacki self-assigned this Aug 7, 2026
Copilot AI lite review requested due to automatic review settings August 7, 2026 18:17
@makubacki
makubacki requested a review from a team as a code owner August 7, 2026 18:17

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR introduces a new RFC proposing updates to the Open Device Partnership’s security policy guidance for handling vulnerabilities identified with AI assistance, aiming to treat such findings as public information to reduce embargo-related risk and delays.

Changes:

  • Adds a new RFC document defining the motivation, goals, and requirements for AI-assisted security bug reporting.
  • Includes “prior art” and a proposed SECURITY.md template update that adds a “Security Bugs Found Using AI” section.
  • Documents alternatives and explicitly scopes out code/design considerations (N/A sections).
Suppressed comments (2)

rfc/0000-ai-security-policy.md:139

  • In GitHub’s branding, “GitHub” should be capitalized as such (currently “Github”).
To do so, please reach out in the form of a
[Github Security Advisory](https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing-information-about-vulnerabilities).

rfc/0000-ai-security-policy.md:40

  • Typo/consistency: “AI assisted” should be hyphenated as the compound adjective “AI-assisted” to match usage elsewhere (e.g., “AI-assisted discovery”).

- The template must state that AI assisted findings are treated as public information.
- Reporters should still avoid posting public information to reproduce the bug, but be ready to offer it privately
  on request.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread rfc/0000-ai-security-policy.md Outdated
Comment thread rfc/0000-ai-security-policy.md
Comment thread rfc/0000-ai-security-policy.md Outdated
@makubacki
makubacki requested a review from Flickdm August 7, 2026 18:19
@makubacki
makubacki force-pushed the update_security_policy_for_ai branch 2 times, most recently from fc001a3 to 74a3283 Compare August 7, 2026 18:24
Comment thread rfc/0000-ai-security-policy.md Outdated
Updates the ODP security policy to account for security bugs found
using AI tools to make handling such findings consistent and efficient
across the organization.

Signed-off-by: Michael Kubacki <michael.kubacki@microsoft.com>
@makubacki
makubacki force-pushed the update_security_policy_for_ai branch from 74a3283 to 885b862 Compare August 11, 2026 16:39
ODP's organization-wide AI policy (RFC 0031) governs how AI tools are used to produce contributions. This RFC addresses
a related but separate topic of how a security bug is handled once AI assistance was used to find it.

## Goals

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should we define a quality bar for AI assisted security bug? Like it has to be reproducible.

Using curl as an example, they get a lot of low quality AI findings.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants