On 07/06/2016 01:15 PM, Anthony G. Basile wrote:
> I'm also disappointed that no one else in the security team has
> recommended any internal policing in response to this.  I maintain that
> forced p.masking and version bumping should not be done by the security
> team but passed to QA for review.  Only QA is mandated with such powers
> by GLEP 48.

We're discussing this in another thread already (i.e possibly a GLEP for
Security project), I'm discussing that as a member of security.

As for any internal policing outside of public policies it is done
within the team and not on a public mailing list. The relevant public
policies are:
https://wiki.gentoo.org/wiki/Project:Security/GLSA_Coordinator_Guide
https://www.gentoo.org/support/security/vulnerability-treatment-policy.html

But I agree these needs reviewing and codification in the form of a
GLEP, but as said in the other thread, need to discuss that within the
project first (I'm not lead, but have requested a team meeting already)

-- 
Kristian Fiskerstrand
OpenPGP certificate reachable at hkp://pool.sks-keyservers.net
fpr:94CB AFDD 3034 5109 5618 35AA 0B7F 8B60 E3ED FAE3

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to