1 |
On 12.09.2012 19:59, Pacho Ramos wrote: |
2 |
> Hello |
3 |
> |
4 |
> Currently, package maintainers are CCed to security bugs when their are |
5 |
> needed. The problem is that, once maintainers add a fixed version and |
6 |
> tell security team they are ok to get it stabilized, maintainers are |
7 |
> kept CCed until bug is closed by security team. This usually means |
8 |
> getting a lot of mail after some time when security team discuss if a |
9 |
> GLSA should be filled or not, if security bot adds some comment... some |
10 |
> of that comments are applied to really old bugs that need no action from |
11 |
> maintainers. |
12 |
> |
13 |
> Maybe would be interesting to change the policy to unCC maintainers |
14 |
> again when their action is no longer required. |
15 |
> |
16 |
> What do you think? |
17 |
|
18 |
Sorta OT but a general thing: I think you should CC teams you want to |
19 |
talk to and not only use the gentoo-systemd-flamewars^W^W-dev mailing |
20 |
list where these teams might only find your post by chance. |
21 |
|
22 |
> |
23 |
> Thanks for your thoughts |
24 |
> |
25 |
-- |
26 |
Alex Legler <a3li@g.o> |
27 |
Gentoo Security/Ruby/Infrastructure |