Re: Fedora Security Team

2020-11-04 Thread Björn Persson
Stephen Gallagher wrote: > Generally, whenever Node.js issues a security release, they do so for > multiple issues simultaneously. When Product Security then goes and creates > Bugzilla tickets, they create many (sometimes up to five bugs per CVE). It > becomes nearly impossible to keep up with

Re: Fedora Security Team

2020-11-04 Thread Justin Forbes
her" > To: "Development discussions related to Fedora" > > Sent: Wednesday, November 4, 2020 8:31:32 PM > Subject: Re: Fedora Security Team > > > > On Tue, Nov 3, 2020 at 11:39 AM Marek Marczykowski-Górecki < > marma...@invisiblethingslab.com > wro

Re: Fedora Security Team

2020-11-04 Thread Huzaifa Sidhpurwala
with SecurityTracking whiteboard if you cant find otherwise. Let me know if you need help, in tracking your fedora security bugs :) - Original Message - From: "Stephen Gallagher" To: "Development discussions related to Fedora" Sent: Wednesday, November 4, 2020 8:31:32 PM Subject:

Re: Fedora Security Team

2020-11-04 Thread Stephen Gallagher
On Tue, Nov 3, 2020 at 11:39 AM Marek Marczykowski-Górecki < marma...@invisiblethingslab.com> wrote: > On Tue, Nov 03, 2020 at 10:02:24AM +, P J P wrote: > > * Right, Fedora package CVEs and relevant bugs are filed by Red Hat > Product security team. > > > > * CVEs/bugs are fixed in the

Re: Fedora Security Team

2020-11-04 Thread Dominik 'Rathann' Mierzejewski
On Tuesday, 03 November 2020 at 17:36, Marek Marczykowski-Górecki wrote: [...] > But by looking at few random items there, it seems the fix is > available in a subsequent upstream release and what is missing is just > bumping the package version in Fedora. "Just bumping" may not always be

Re: Fedora Security Team

2020-11-04 Thread Petr Pisar
On Tue, Nov 03, 2020 at 05:47:28PM +0100, Dominique Martinet wrote: > Marek Marczykowski-Górecki wrote on Tue, Nov 03, 2020: > > Do you know if some parts of the above already exist? I know Debian has > > automatic checks for latest upstream versions, but I haven't seen it in > > Fedora. > >

Re: Fedora Security Team

2020-11-03 Thread Dominique Martinet
Marek Marczykowski-Górecki wrote on Tue, Nov 03, 2020: > Do you know if some parts of the above already exist? I know Debian has > automatic checks for latest upstream versions, but I haven't seen it in > Fedora. Fedora has "Upstream Release Monitoring"

Re: Fedora Security Team

2020-11-03 Thread Marek Marczykowski-Górecki
On Tue, Nov 03, 2020 at 10:02:24AM +, P J P wrote: > * Right, Fedora package CVEs and relevant bugs are filed by Red Hat Product > security team. > > * CVEs/bugs are fixed in the upstream sources first. Fedora package > maintainers do rebuild >   of the package with released fixes. I see

Re: Fedora Security Team

2020-11-03 Thread P J P
s and relevant bugs are filed by Red Hat Product security team. * CVEs/bugs are fixed in the upstream sources first. Fedora package maintainers do rebuild   of the package with released fixes. * Often, Fedora package maintainer is also an upstream developer/maintainer.   It helps to fix issues

Re: Fedora Security Team

2020-11-02 Thread Michael Catanzaro
On Tue, Nov 3, 2020 at 12:53 am, Marek Marczykowski-Górecki wrote: How are in practice security issues handled in Fedora? Is there an active security team to help patching those in timely manner? Or is it responsibility of individual package maintainers only? Hi, Red Hat Product Security is

Fedora Security Team

2020-11-02 Thread Marek Marczykowski-Górecki
Hello all, How are in practice security issues handled in Fedora? Is there an active security team to help patching those in timely manner? Or is it responsibility of individual package maintainers only? I've tried to find some information on that, but the only thing I've found is this page:

Fedora Security Team

2014-07-30 Thread Eric H. Christensen
. [0] https://fedoraproject.org/wiki/Security_Team [1] https://lists.fedoraproject.org/mailman/listinfo/security-team [2] #fedora-security-team on irc.freenode.net - -- Eric - -- Eric Sparks Christensen Fedora Project spa...@fedoraproject.org - spa