1 |
On Thu, Mar 18, 2004 at 02:57:14PM +0100 or thereabouts, Koon wrote: |
2 |
> Could you detail in what areas help is needed, so that we can evaluate |
3 |
> if our profiles (free time and knowledge) can fit in ? |
4 |
|
5 |
We need folks to monitor bugzilla for security-related postings and then |
6 |
push valid postings through the GLSA process. |
7 |
|
8 |
> However I had concern recently with the latest kernel GLSA which has |
9 |
> been over-delayed in my opinion. I've posted about this in this |
10 |
> mailing-list so that we can discuss steps to avoid such delays in the |
11 |
> future, but with no answer from the official people in charge. |
12 |
|
13 |
Kernel GLSAs are difficult because we can't release the GLSA until all our |
14 |
kernels have been patched. Our kernel team is also short-staffed, so that |
15 |
takes time. Know any good kernel hackers that want to help out? Send them |
16 |
my way and I'll make sure they get put in touch with the right person. |
17 |
|
18 |
> There is one point where I agree with Tobias : too many GLSA diffusion |
19 |
> channels might increase the potential sync problems. gentoo main page, |
20 |
> forums, mailing-list(s), GLSA-test hub... I think we have to be careful |
21 |
> about that. |
22 |
|
23 |
gentoo-announce is *the* official means of distributing GLSAs. If you want |
24 |
to make sure you receive all GLSAs, sign up for that. We also publish to |
25 |
external lists as a "best practice" and a way to reach out to the larger |
26 |
Linux community to ensure they're aware of vulnerabilities as well. |
27 |
|
28 |
--kurt |