Gentoo Archives: gentoo-dev

From: Alex Legler <a3li@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Re: RFC Bugzilla interaction guide for devs & editbugs users
Date: Mon, 06 Sep 2010 12:36:58
Message-Id: 20100906143631.70dd8cb6@mail.a3li.li
In Reply to: [gentoo-dev] Re: RFC Bugzilla interaction guide for devs & editbugs users by Christian Faulhammer
1 On Mon, 6 Sep 2010 14:10:41 +0200, Christian Faulhammer
2 <fauli@g.o> wrote:
3
4 > Hi,
5 >
6 > "Robin H. Johnson" <robbat2@g.o>:
7 > > 2.2. Security bugs
8 > > The developer should comment, but ONLY members of the security
9 > > team should:
10 > > - change whiteboard
11 > > - add/remove arches
12 >
13 > As security may be grateful for any kind of help, those two actions
14 > is often done by the maintainers.
15 >
16
17 We are indeed grateful for help, but we require people who change
18 things there to know what they are doing.
19
20 I understand that we're slow at times, but we regularly have to revisit
21 a bug because there was a change, but it wasn't done right.
22 That's no help. Instead, it's creating more work (and frustration).
23
24 There is a specific guideline on how we handle our bugs, and we request
25 people who change bugs assigned to our team to follow them or to stay
26 away.
27
28 So, as for the guide, it should link to the vulnerability policy as
29 well include a note with the contents of the previous paragraph.
30
31 --
32 Alex Legler | Gentoo Security / Ruby
33 a3li@g.o | a3li@××××××××××.de

Attachments

File name MIME type
signature.asc application/pgp-signature