1 |
On Mon, 6 Sep 2010 14:10:41 +0200, Christian Faulhammer |
2 |
<fauli@g.o> wrote: |
3 |
|
4 |
> Hi, |
5 |
> |
6 |
> "Robin H. Johnson" <robbat2@g.o>: |
7 |
> > 2.2. Security bugs |
8 |
> > The developer should comment, but ONLY members of the security |
9 |
> > team should: |
10 |
> > - change whiteboard |
11 |
> > - add/remove arches |
12 |
> |
13 |
> As security may be grateful for any kind of help, those two actions |
14 |
> is often done by the maintainers. |
15 |
> |
16 |
|
17 |
We are indeed grateful for help, but we require people who change |
18 |
things there to know what they are doing. |
19 |
|
20 |
I understand that we're slow at times, but we regularly have to revisit |
21 |
a bug because there was a change, but it wasn't done right. |
22 |
That's no help. Instead, it's creating more work (and frustration). |
23 |
|
24 |
There is a specific guideline on how we handle our bugs, and we request |
25 |
people who change bugs assigned to our team to follow them or to stay |
26 |
away. |
27 |
|
28 |
So, as for the guide, it should link to the vulnerability policy as |
29 |
well include a note with the contents of the previous paragraph. |
30 |
|
31 |
-- |
32 |
Alex Legler | Gentoo Security / Ruby |
33 |
a3li@g.o | a3li@××××××××××.de |