Gentoo Archives: gentoo-dev

From: Michael Palimaka <kensington@g.o>
To: gentoo-dev@l.g.o
Cc: Pacho Ramos <pacho@g.o>
Subject: [gentoo-dev] Re: About changing security policy to unCC maintainers when their are not needed
Date: Wed, 12 Sep 2012 18:32:04
Message-Id: 5050D4AF.1010205@gentoo.org
In Reply to: [gentoo-dev] About changing security policy to unCC maintainers when their are not needed by Pacho Ramos
1 On 2012-09-13 03:59, Pacho Ramos wrote:
2 > Hello
3 >
4 > Currently, package maintainers are CCed to security bugs when their are
5 > needed. The problem is that, once maintainers add a fixed version and
6 > tell security team they are ok to get it stabilized, maintainers are
7 > kept CCed until bug is closed by security team. This usually means
8 > getting a lot of mail after some time when security team discuss if a
9 > GLSA should be filled or not, if security bot adds some comment... some
10 > of that comments are applied to really old bugs that need no action from
11 > maintainers.
12 >
13 > Maybe would be interesting to change the policy to unCC maintainers
14 > again when their action is no longer required.
15 >
16 > What do you think?
17 >
18 > Thanks for your thoughts
19 >
20
21 Hello,
22
23 Is the policy you describe officially documented, or just current behaviour?
24
25 In KDE and Qt herds for example, we usually just unCC ourselves when
26 we've taken the required action.
27
28 Best regards,
29 Michael

Replies