PHP
NO
PHP, Security & PSR-9/PSR-10
[]
blog.phpdeveloper.org
Here’s a brief summary so far:At the end of last year (2014) Lukas Smith made a proposal to the PHP-FIG group for a standard that would make reporting security issues with PHP projects and libraries a much more structured thing.
in a project’s repository would provide information about current and past security issues in a well-defined structure that could have some automated tooling around it.
So, the original PSR-9 was split, giving us the security advisory reporting standard (PSR-9) and the security disclosure workflow (PSR-10) to make discovery of the reports easier.
PSR-9The main goal of the PSR-9 standard is to provide structure around the documentation a project provides to the wider community around security vulnerabilities that have been found (and fixed) and those that are still pending.
The PSR-9 proposal provides a lot more context around the security issues too.
['document'
'reporting'
'psr9'
'issues'
'psr9psr10'
'vulnerabilities'
'psr10'
'security'
'projects'
'information'
'php'
'project']