Gentoo Archives: gentoo-project

From: Aaron Bauman <bman@g.o>
To: gentoo-project@l.g.o
Subject: Re: [gentoo-project] Re: [pre-glep] Security Project Structure
Date: Tue, 04 Dec 2018 22:35:26
Message-Id: 20181204223520.GO16376@monkey
In Reply to: Re: [gentoo-project] Re: [pre-glep] Security Project Structure by Kristian Fiskerstrand
1 On Tue, Dec 04, 2018 at 11:17:01PM +0100, Kristian Fiskerstrand wrote:
2 > Well, in terms of CVEs the documentation matters quite a bit, the
3 > question isn't necessarily what any user would do ... but what a
4 > reasonable user would do.. and a reasonable user would consider the
5 > documented practices of a project.
6 >
7
8 I suppose a "reasonable user" by your definition would also read and
9 track the CVE's to determine the security posture of their machine
10 on their own?
11
12 If so, we can disband the security team on that logic.
13
14 > --
15 > Kristian Fiskerstrand
16 > OpenPGP keyblock reachable at hkp://pool.sks-keyservers.net
17 > fpr:94CB AFDD 3034 5109 5618 35AA 0B7F 8B60 E3ED FAE3
18 >
19
20
21
22
23 --
24 Cheers,
25 Aaron

Attachments

File name MIME type
signature.asc application/pgp-signature