Add security patch release process documentation #5987
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
The documentation of our standard and patch release processes does not, at present, include the steps required to build a security patch release, so we add two sections which describe how we build such releases.
The first new section documents our normal security patch release process, which applies when we do not need to coordinate our release with other projects, or at least do not need to build release assets in private while under a publication embargo.
The second new section details the process of building new Git LFS release binaries in private, so they can be shared with other downstream projects while we are under an embargo on the publication of the security vulnerability and associated security patch release.