Gentoo Archives: gentoo-dev

From: Kristian Fiskerstrand <k_f@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] RFC: Pre-GLEP: Security Project
Date: Wed, 15 Mar 2017 12:06:43
Message-Id: 5e57e1df-537c-f62f-ed1d-a640b7b277a8@gentoo.org
In Reply to: Re: [gentoo-dev] RFC: Pre-GLEP: Security Project by Alexis Ballier
1 On 03/15/2017 08:12 AM, Alexis Ballier wrote:
2 > On Tue, 14 Mar 2017 19:55:44 -0400
3
4
5 >
6 >
7 > Agreed, but I was under the impression that sometimes sec. team was
8 > waiting for cleanup to close a bug. If you've just done the analysis
9 > that it is the only thing left, just do it and close the bug, instead
10 > of pinging on the bug and re-do that analysis in a later pass. This
11 > reduces context switches and makes everything more efficient :)
12 >
13
14
15 Indeed, although it should be noted that the amount of context switches
16 is reduced by using whiteboards to tag status along with version
17 information in summary, which is why it is important they follow
18 security team policies for security bugs.
19
20 In particular the whiteboard status allows for effective filtering when
21 creating work-lists to reduce context switching (so if you're a
22 maintainer starting a stablereq, feel free to update whiteboard from
23 ebuild to stable!)
24
25 --
26 Kristian Fiskerstrand
27 OpenPGP keyblock reachable at hkp://pool.sks-keyservers.net
28 fpr:94CB AFDD 3034 5109 5618 35AA 0B7F 8B60 E3ED FAE3

Attachments

File name MIME type
signature.asc application/pgp-signature