Trademark Usage Approval Request for FedoraCVE.org #552
Labels
No labels
category
budget
category
code-of-conduct
category
docs
category
elections
category
events
category
initiatives
category
mindshare
category
policies
category
spending-request
category
Strategy Summit
category
trademarks
Next Meeting
state
resolved
good first issue
help wanted
needs
changes
needs
reporter feedback
needs
triage
needs
vote
role
engineering
role
fca
role
foa
role
fpl
role
initiative lead
role
mindshare
scope
bug
scope
improvement
scope
new
state
approved
state
blocked
state
duplicate
state
invalid
state
wontfix
No milestone
No project
No assignees
3 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
council/tickets#552
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Hello Fedora Council
We recently launched FedoraCVE.org, a community driven, non profit initiative built by two experienced security engineers from Red Hat Product Security (darunesh@redhat.com and saroy@redhat.com). Our goal is to improve visibility into Fedora related CVEs and provide clearer insight into the security status of packages across the Fedora ecosystem. After announcing the project, we learned that using the "Fedora" name and trademarks requires Council approval, and we sincerely apologize for this oversight.
We created this platform because Fedora users today lack authoritative, timely clarity on vulnerability status - whether a CVE is acknowledged, unfixed, silently fixed, or under investigation. This information gap introduces real security risk and undermines trust for both users and maintainers. A structured reporting approach, such as official VEX-style communication, would offer transparency, predictability, and a stronger overall security posture for Fedora.
For this initiative, we have acquired the domains fedoracve.org and the codebase is hosted at: https://github.com/FedoraCVE/fedora-cve-dashboard. We respectfully request formal review and approval of the project's name and trademark usage.
Metadata Update from @jflory7:
See linked Fedora Discussion topic for Ticket 552
Discussed in 2025-12-03 Fedora Council meeting.
The Council discussed the request to use the Fedora logo on fedoracve.org. While supportive of the initiative, the Council voted (+8) to grant conditional approval only. This approval is not final and is strictly contingent upon a review and decision by Red Hat Legal regarding trademark usage.
The specific agreed-upon statement from the meeting is as follows:
@jspaleta has been actioned to initiate the required review with Red Hat Legal.
Metadata Update from @jflory7:
Gentle check-in here — this has been quiet since December while we wait on the Red Hat Legal review mentioned above. This ticket is currently milestoned to Fedora Linux 44, which is now past due, so it needs to move.
Current open milestones and due dates:
@amoloney, could you help triage which milestone makes sense for this one, and flag whether it needs dedicated meeting time to move forward, or if we're still just waiting on Legal?
Assisted-by: Claude Sonnet 5 (1M context)
@jspaleta have you sent this to Legal yet?
@bytehackr have you and your team reviewed the Fedora Councils conditional approval requirements and are happy to proceed under that guidance?
I dont think this needs to be bound to any release milestone, it just needs to be followed up with, but I suspect the milestone assignment is to keep manners on us at council :)