1 |
On Tue, March 10, 2009 7:07 am, Duncan wrote: |
2 |
> Gordon Malm <gengor@g.o> posted |
3 |
> 200903091617.48682.gengor@g.o, excerpted below, on Mon, 09 Mar |
4 |
> 2009 16:17:48 -0700: |
5 |
> |
6 |
>> There is an important security aspect to retiring folks - commit |
7 |
>> abilities. Perhaps in the case a dev wants to contribute but cannot in |
8 |
>> the near future their commit privs can just be revoked until such time |
9 |
>> they ask for them to be turned back on? I guess that would be an |
10 |
>> 'extended devaway' ? |
11 |
> |
12 |
|
13 |
[...] |
14 |
|
15 |
> We don't want some still active authorization and key |
16 |
> from two years ago getting stolen and used to try to slip a bad commit |
17 |
> under the radar [...] |
18 |
|
19 |
With some devs reviewing gentoo-commits@, I highly doubt that this commit |
20 |
could go unnoticed more than a few hours. |
21 |
|
22 |
-- |
23 |
Pierre-Yves Rofes |
24 |
Gentoo Linux Security Team |