On Mon, Aug 10, 2026 at 04:22:41PM +0200, Peter Krempa via Devel wrote:
> From: Peter Krempa <[email protected]>
> 
> Archives (as witnessed by recent reports) hide useful information by
> requiring the maintainer to download the archive which may be dangerous.
> 
> Recent submissions also contained a lot of fluff inside the archives.
> 
> Instruct submitters of security issues to attach files directly instead
> of hiding them in an archive.
> 
> Signed-off-by: Peter Krempa <[email protected]>
> ---
>  docs/securityprocess.rst | 4 ++++
>  1 file changed, 4 insertions(+)
> 
> diff --git a/docs/securityprocess.rst b/docs/securityprocess.rst
> index b9fa8d9890..d1e7fcc424 100644
> --- a/docs/securityprocess.rst
> +++ b/docs/securityprocess.rst
> @@ -20,6 +20,10 @@ apply to the core project.
>  Ensure that the "**turn on confidentiality**" checkbox is selected prior to
>  submitting the issue, to restrict visibility to project maintainers only.
> 
> +.. important::
> +   Only attach plain files, do not bundle files in archives without prior 
> request
> +   from a libvirt maintainer.

I wonder if we should be more explicit

   "..do not bundle files in archives (zip, tar, etc) without prior..."

Either way,

Reviewed-by: Daniel P. Berrangé <[email protected]>


With regards,
Daniel
-- 
|: https://berrange.com       ~~        https://hachyderm.io/@berrange :|
|: https://libvirt.org          ~~          https://entangle-photo.org :|
|: https://pixelfed.art/berrange   ~~    https://fstop138.berrange.com :|

Reply via email to