1 |
On 2012-09-13 03:59, Pacho Ramos wrote: |
2 |
> Hello |
3 |
> |
4 |
> Currently, package maintainers are CCed to security bugs when their are |
5 |
> needed. The problem is that, once maintainers add a fixed version and |
6 |
> tell security team they are ok to get it stabilized, maintainers are |
7 |
> kept CCed until bug is closed by security team. This usually means |
8 |
> getting a lot of mail after some time when security team discuss if a |
9 |
> GLSA should be filled or not, if security bot adds some comment... some |
10 |
> of that comments are applied to really old bugs that need no action from |
11 |
> maintainers. |
12 |
> |
13 |
> Maybe would be interesting to change the policy to unCC maintainers |
14 |
> again when their action is no longer required. |
15 |
> |
16 |
> What do you think? |
17 |
> |
18 |
> Thanks for your thoughts |
19 |
> |
20 |
|
21 |
Hello, |
22 |
|
23 |
Is the policy you describe officially documented, or just current behaviour? |
24 |
|
25 |
In KDE and Qt herds for example, we usually just unCC ourselves when |
26 |
we've taken the required action. |
27 |
|
28 |
Best regards, |
29 |
Michael |