1 |
On 07/06/2016 01:15 PM, Anthony G. Basile wrote: |
2 |
> I'm also disappointed that no one else in the security team has |
3 |
> recommended any internal policing in response to this. I maintain that |
4 |
> forced p.masking and version bumping should not be done by the security |
5 |
> team but passed to QA for review. Only QA is mandated with such powers |
6 |
> by GLEP 48. |
7 |
|
8 |
We're discussing this in another thread already (i.e possibly a GLEP for |
9 |
Security project), I'm discussing that as a member of security. |
10 |
|
11 |
As for any internal policing outside of public policies it is done |
12 |
within the team and not on a public mailing list. The relevant public |
13 |
policies are: |
14 |
https://wiki.gentoo.org/wiki/Project:Security/GLSA_Coordinator_Guide |
15 |
https://www.gentoo.org/support/security/vulnerability-treatment-policy.html |
16 |
|
17 |
But I agree these needs reviewing and codification in the form of a |
18 |
GLEP, but as said in the other thread, need to discuss that within the |
19 |
project first (I'm not lead, but have requested a team meeting already) |
20 |
|
21 |
-- |
22 |
Kristian Fiskerstrand |
23 |
OpenPGP certificate reachable at hkp://pool.sks-keyservers.net |
24 |
fpr:94CB AFDD 3034 5109 5618 35AA 0B7F 8B60 E3ED FAE3 |