Gentoo Archives: gentoo-dev

From: Kristian Fiskerstrand <k_f@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] why is the security team running around p.masking packages
Date: Wed, 06 Jul 2016 11:30:56
Message-Id: e446f77f-4c34-be66-28aa-aa5a32892be4@gentoo.org
In Reply to: Re: [gentoo-dev] why is the security team running around p.masking packages by "Anthony G. Basile"
1 On 07/06/2016 01:15 PM, Anthony G. Basile wrote:
2 > I'm also disappointed that no one else in the security team has
3 > recommended any internal policing in response to this. I maintain that
4 > forced p.masking and version bumping should not be done by the security
5 > team but passed to QA for review. Only QA is mandated with such powers
6 > by GLEP 48.
7
8 We're discussing this in another thread already (i.e possibly a GLEP for
9 Security project), I'm discussing that as a member of security.
10
11 As for any internal policing outside of public policies it is done
12 within the team and not on a public mailing list. The relevant public
13 policies are:
14 https://wiki.gentoo.org/wiki/Project:Security/GLSA_Coordinator_Guide
15 https://www.gentoo.org/support/security/vulnerability-treatment-policy.html
16
17 But I agree these needs reviewing and codification in the form of a
18 GLEP, but as said in the other thread, need to discuss that within the
19 project first (I'm not lead, but have requested a team meeting already)
20
21 --
22 Kristian Fiskerstrand
23 OpenPGP certificate reachable at hkp://pool.sks-keyservers.net
24 fpr:94CB AFDD 3034 5109 5618 35AA 0B7F 8B60 E3ED FAE3

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-dev] why is the security team running around p.masking packages "Anthony G. Basile" <blueness@g.o>