Gentoo Archives: gentoo-dev

From: Jason Wever <weeve@g.o>
To: Gentoo Dev Mailing List <gentoo-dev@l.g.o>
Subject: Re: [gentoo-dev] Testing instructions for security bugs
Date: Tue, 24 Aug 2004 03:58:13
Message-Id: Pine.LNX.4.61.0408232155140.31215@stargazer.weeve.org
In Reply to: Re: [gentoo-dev] Testing instructions for security bugs by Kurt Lieber
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 On Mon, 23 Aug 2004, Kurt Lieber wrote:
5
6 > While I am not opposed to the idea, the security team isn't in a position
7 > to take on this responsibility. We don't have the staffing (or, quite
8 > frankly, the interest) to figure out how to use every single package in our
9 > tree.
10
11 I agree. Having security come up with these test cases is almost a
12 replica of what is trying to be avoided. As package maintainers are
13 normally involved in the security bugs for said package, I don't think
14 this should be a big stretch.
15
16 Plus coming up with a test case for a security bug eases the pain when you
17 start slapping us arch people around to bump your package to a new stable
18 rev :)
19
20 - --
21 Jason Wever
22 Gentoo/Sparc Co-Team Lead
23 -----BEGIN PGP SIGNATURE-----
24 Version: GnuPG v1.2.4 (GNU/Linux)
25
26 iD8DBQFBKrzRdKvgdVioq28RAme8AJ4xrxzYMZfj8vBTLrBgiqnTpyqXrgCgkMkj
27 iTBW9yQ2FdHsaytyKL5nZJQ=
28 =ytiY
29 -----END PGP SIGNATURE-----
30
31 --
32 gentoo-dev@g.o mailing list

Replies

Subject Author
Re: [gentoo-dev] Testing instructions for security bugs Lars Weiler <pylon@g.o>