Gentoo Archives: gentoo-dev

From: Pacho Ramos <pacho@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] About changing security policy to unCC maintainers when their are not needed
Date: Thu, 13 Sep 2012 19:59:42
Message-Id: 1347566254.4821.5.camel@belkin4
In Reply to: Re: [gentoo-dev] About changing security policy to unCC maintainers when their are not needed by Alex Legler
1 El jue, 13-09-2012 a las 15:48 +0200, Alex Legler escribió:
2 > On 12.09.2012 19:59, Pacho Ramos wrote:
3 > > Hello
4 > >
5 > > Currently, package maintainers are CCed to security bugs when their are
6 > > needed. The problem is that, once maintainers add a fixed version and
7 > > tell security team they are ok to get it stabilized, maintainers are
8 > > kept CCed until bug is closed by security team. This usually means
9 > > getting a lot of mail after some time when security team discuss if a
10 > > GLSA should be filled or not, if security bot adds some comment... some
11 > > of that comments are applied to really old bugs that need no action from
12 > > maintainers.
13 > >
14 > > Maybe would be interesting to change the policy to unCC maintainers
15 > > again when their action is no longer required.
16 > >
17 > > What do you think?
18 >
19 > Sorta OT but a general thing: I think you should CC teams you want to
20 > talk to and not only use the gentoo-systemd-flamewars^W^W-dev mailing
21 > list where these teams might only find your post by chance.
22 >
23 > >
24 > > Thanks for your thoughts
25 > >
26
27 I thought all developers were subscribed to gentoo-dev and would read
28 it :|

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies