Trademark Usage Approval Request for FedoraCVE.org #552

Open
opened 2025-11-26 09:51:51 +00:00 by bytehackr · 6 comments

Hello Fedora Council

We recently launched FedoraCVE.org, a community driven, non profit initiative built by two experienced security engineers from Red Hat Product Security (darunesh@redhat.com and saroy@redhat.com). Our goal is to improve visibility into Fedora related CVEs and provide clearer insight into the security status of packages across the Fedora ecosystem. After announcing the project, we learned that using the "Fedora" name and trademarks requires Council approval, and we sincerely apologize for this oversight.

We created this platform because Fedora users today lack authoritative, timely clarity on vulnerability status - whether a CVE is acknowledged, unfixed, silently fixed, or under investigation. This information gap introduces real security risk and undermines trust for both users and maintainers. A structured reporting approach, such as official VEX-style communication, would offer transparency, predictability, and a stronger overall security posture for Fedora.

For this initiative, we have acquired the domains fedoracve.org and the codebase is hosted at: https://github.com/FedoraCVE/fedora-cve-dashboard. We respectfully request formal review and approval of the project's name and trademark usage.

Screenshot_2025-11-26_at_15-20-40_Fedora_CVE_Dashboard_-_Security_Monitoring.png
Screenshot_2025-11-26_at_15-20-25_Advanced_Package_Analytics_-_Fedora_CVE_Dashboard.png

Hello Fedora Council We recently launched FedoraCVE.org, a community driven, non profit initiative built by two experienced security engineers from Red Hat Product Security (darunesh@redhat.com and saroy@redhat.com). Our goal is to improve visibility into Fedora related CVEs and provide clearer insight into the security status of packages across the Fedora ecosystem. After announcing the project, we learned that using the "Fedora" name and trademarks requires Council approval, and we sincerely apologize for this oversight. We created this platform because Fedora users today lack authoritative, timely clarity on vulnerability status - whether a CVE is acknowledged, unfixed, silently fixed, or under investigation. This information gap introduces real security risk and undermines trust for both users and maintainers. A structured reporting approach, such as official VEX-style communication, would offer transparency, predictability, and a stronger overall security posture for Fedora. For this initiative, we have acquired the domains fedoracve.org and the codebase is hosted at: https://github.com/FedoraCVE/fedora-cve-dashboard. We respectfully request formal review and approval of the project's name and trademark usage. [![Screenshot_2025-11-26_at_15-20-40_Fedora_CVE_Dashboard_-_Security_Monitoring.png](/Fedora-Council/tickets/issue/raw/files/e3704ca347f2ba0b8644b5f8d29f3e89d929489b926113b6606ac281e9161570-Screenshot_2025-11-26_at_15-20-40_Fedora_CVE_Dashboard_-_Security_Monitoring.png)](/Fedora-Council/tickets/issue/raw/files/e3704ca347f2ba0b8644b5f8d29f3e89d929489b926113b6606ac281e9161570-Screenshot_2025-11-26_at_15-20-40_Fedora_CVE_Dashboard_-_Security_Monitoring.png) [![Screenshot_2025-11-26_at_15-20-25_Advanced_Package_Analytics_-_Fedora_CVE_Dashboard.png](/Fedora-Council/tickets/issue/raw/files/d476040b2fd81a5302b1c429c54bf323f5acd5dd1c86455e64dc066d1e6342d1-Screenshot_2025-11-26_at_15-20-25_Advanced_Package_Analytics_-_Fedora_CVE_Dashboard.png)](/Fedora-Council/tickets/issue/raw/files/d476040b2fd81a5302b1c429c54bf323f5acd5dd1c86455e64dc066d1e6342d1-Screenshot_2025-11-26_at_15-20-25_Advanced_Package_Analytics_-_Fedora_CVE_Dashboard.png)
Owner

Metadata Update from @jflory7:

  • Issue tagged with: Next Meeting, trademarks
**Metadata Update from @jflory7**: - Issue tagged with: Next Meeting, trademarks
Owner
## [_See linked Fedora Discussion topic for Ticket 552_](https://discussion.fedoraproject.org/t/fedora-council-tickets-ticket-552-trademark-usage-approval-request-for-fedoracve-org/174904)
Owner

Discussed in 2025-12-03 Fedora Council meeting.


The Council discussed the request to use the Fedora logo on fedoracve.org. While supportive of the initiative, the Council voted (+8) to grant conditional approval only. This approval is not final and is strictly contingent upon a review and decision by Red Hat Legal regarding trademark usage.

The specific agreed-upon statement from the meeting is as follows:

The Fedora Council conditionally approves the use of the Fedora logo on the fedoracve.org website, pending final approval from Red Hat Legal trademark experts.

The Fedora Council RECOMMENDS the use of a clear disclaimer on the site that the site is not officially managed or run by the Fedora community (to avoid our Fedora Infra team getting support requests when there are issues), AND does not represent the state or management of CVEs in Fedora Linux.

The Fedora Council RECOMMENDS transferring ownership of the domain to Red Hat IT so it can be maintained and renewed in perpetuity by those responsible for the Fedora trademark.

@jspaleta has been actioned to initiate the required review with Red Hat Legal.

_Discussed in [2025-12-03 Fedora Council meeting](https://discussion.fedoraproject.org/t/fedora-council-meeting-2025-12-03-image-mode-initiative-renewal-fedoracve-org-trademark-weblate-t-cs/175583)_. --- The Council discussed the request to use the Fedora logo on fedoracve.org. While supportive of the initiative, the Council voted (+8) to grant conditional approval only. This approval is not final and is strictly contingent upon a review and decision by Red Hat Legal regarding trademark usage. The specific agreed-upon statement from the meeting is as follows: > The Fedora Council conditionally approves the use of the Fedora logo on the fedoracve.org website, pending final approval from Red Hat Legal trademark experts. > > The Fedora Council RECOMMENDS the use of a clear disclaimer on the site that the site is not officially managed or run by the Fedora community (to avoid our Fedora Infra team getting support requests when there are issues), AND does not represent the state or management of CVEs in Fedora Linux. > > The Fedora Council RECOMMENDS transferring ownership of the domain to Red Hat IT so it can be maintained and renewed in perpetuity by those responsible for the Fedora trademark. @jspaleta has been actioned to initiate the required review with Red Hat Legal.
Owner

Metadata Update from @jflory7:

  • Issue untagged with: Next Meeting
  • Issue assigned to jspaleta
**Metadata Update from @jflory7**: - Issue **un**tagged with: Next Meeting - Issue assigned to jspaleta
jflory7 added this to the Fedora Linux 44 milestone 2026-02-18 23:51:00 +00:00
Owner

Gentle check-in here — this has been quiet since December while we wait on the Red Hat Legal review mentioned above. This ticket is currently milestoned to Fedora Linux 44, which is now past due, so it needs to move.

Current open milestones and due dates:

@amoloney, could you help triage which milestone makes sense for this one, and flag whether it needs dedicated meeting time to move forward, or if we're still just waiting on Legal?

Assisted-by: Claude Sonnet 5 (1M context)

Gentle check-in here — this has been quiet since December while we wait on the Red Hat Legal review mentioned above. This ticket is currently milestoned to Fedora Linux 44, which is now past due, so it needs to move. Current open milestones and due dates: - [Fedora Linux 45](https://forge.fedoraproject.org/council/tickets/milestone/670) — due 2026-10-20 - [Fedora Linux 46](https://forge.fedoraproject.org/council/tickets/milestone/1535) — due 2027-04-20 - [Flock 2027](https://forge.fedoraproject.org/council/tickets/milestone/1536) — due 2027-06-15 @amoloney, could you help triage which milestone makes sense for this one, and flag whether it needs dedicated meeting time to move forward, or if we're still just waiting on Legal? <sub>_Assisted-by: Claude Sonnet 5 (1M context)_</sub>
Owner

@jspaleta have you sent this to Legal yet?

@bytehackr have you and your team reviewed the Fedora Councils conditional approval requirements and are happy to proceed under that guidance?

I dont think this needs to be bound to any release milestone, it just needs to be followed up with, but I suspect the milestone assignment is to keep manners on us at council :)

@jspaleta have you sent this to Legal yet? @bytehackr have you and your team reviewed the Fedora Councils conditional approval requirements and are happy to proceed under that guidance? I dont think this needs to be bound to any release milestone, it just needs to be followed up with, but I suspect the milestone assignment is to keep manners on us at council :)
Sign in to join this conversation.
No milestone
No assignees
3 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
council/tickets#552
No description provided.