Gentoo Archives: gentoo-dev

From: Pierre-Yves Rofes <py@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Re: Developer Retirements
Date: Tue, 10 Mar 2009 10:23:34
Message-Id: a4345526fd26a2a6f5dd3cccb4e9767d.squirrel@mail.rofes.fr
In Reply to: [gentoo-dev] Re: Developer Retirements by Duncan <1i5t5.duncan@cox.net>
1 On Tue, March 10, 2009 7:07 am, Duncan wrote:
2 > Gordon Malm <gengor@g.o> posted
3 > 200903091617.48682.gengor@g.o, excerpted below, on Mon, 09 Mar
4 > 2009 16:17:48 -0700:
5 >
6 >> There is an important security aspect to retiring folks - commit
7 >> abilities. Perhaps in the case a dev wants to contribute but cannot in
8 >> the near future their commit privs can just be revoked until such time
9 >> they ask for them to be turned back on? I guess that would be an
10 >> 'extended devaway' ?
11 >
12
13 [...]
14
15 > We don't want some still active authorization and key
16 > from two years ago getting stolen and used to try to slip a bad commit
17 > under the radar [...]
18
19 With some devs reviewing gentoo-commits@, I highly doubt that this commit
20 could go unnoticed more than a few hours.
21
22 --
23 Pierre-Yves Rofes
24 Gentoo Linux Security Team

Replies

Subject Author
[gentoo-dev] Re: Developer Retirements Duncan <1i5t5.duncan@×××.net>
Re: [gentoo-dev] Re: Developer Retirements Alec Warner <antarus@g.o>