Gentoo Archives: gentoo-dev

From: Agostino Sarubbo <ago@g.o>
To: gentoo-dev@l.g.o
Cc: security@g.o, "Michał Górny" <mgorny@g.o>
Subject: Re: [gentoo-dev] [RFC] Decoupling stabilization from security bugs
Date: Thu, 12 Aug 2021 15:17:47
Message-Id: 2076514.irdbgypaU6@spectre
In Reply to: [gentoo-dev] [RFC] Decoupling stabilization from security bugs by "Michał Górny"
1 On giovedì 12 agosto 2021 14:53:33 CEST Michał Górny wrote:
2 > To resolve these problems going forward and establish consistent
3 > behavior in the future, I'd like to propose to disable 'package list'
4 > fields on security bugs and instead expect regular stabilization bugs to
5 > be used (and made block the security bugs) for stabilizations. While I
6 > understand that filing additional bugs might be cumbersome for some
7 > people, I don't think it's such a herculean effort to outweigh
8 > the problems solved.
9
10 I think it is a good idea but the stabilization bug that blocks the security
11 bug should at least have something (bugzilla KEYWORD?) to facilitate the
12 search of the security stabilization.
13 Atm we look for bugs with assignee = security@ and cc = arch@
14
15
16 Agostino

Replies