1 |
On Wed, 12 Sep 2012 19:59:01 +0200 |
2 |
Pacho Ramos <pacho@g.o> wrote: |
3 |
|
4 |
> Hello |
5 |
> |
6 |
> Currently, package maintainers are CCed to security bugs when their |
7 |
> are needed. The problem is that, once maintainers add a fixed version |
8 |
> and tell security team they are ok to get it stabilized, maintainers |
9 |
> are kept CCed until bug is closed by security team. This usually means |
10 |
> getting a lot of mail after some time when security team discuss if a |
11 |
> GLSA should be filled or not, if security bot adds some comment... |
12 |
> some of that comments are applied to really old bugs that need no |
13 |
> action from maintainers. |
14 |
|
15 |
So you would want to be re-CC'd when it is time to remove the vulnerable |
16 |
versions, I guess. |
17 |
|
18 |
Also, I have problems with stating "getting too much mail" as the |
19 |
actual problem. Perhaps your brain or your computer can smartly filter |
20 |
them out? |
21 |
|
22 |
> Maybe would be interesting to change the policy to unCC maintainers |
23 |
> again when their action is no longer required. |
24 |
|
25 |
You can un-CC yourself. I don't see why security@ should be doing the |
26 |
legwork. |
27 |
|
28 |
|
29 |
jer |