On 07/06/2016 01:15 PM, Anthony G. Basile wrote: > I'm also disappointed that no one else in the security team has > recommended any internal policing in response to this. I maintain that > forced p.masking and version bumping should not be done by the security > team but passed to QA for review. Only QA is mandated with such powers > by GLEP 48.
We're discussing this in another thread already (i.e possibly a GLEP for Security project), I'm discussing that as a member of security. As for any internal policing outside of public policies it is done within the team and not on a public mailing list. The relevant public policies are: https://wiki.gentoo.org/wiki/Project:Security/GLSA_Coordinator_Guide https://www.gentoo.org/support/security/vulnerability-treatment-policy.html But I agree these needs reviewing and codification in the form of a GLEP, but as said in the other thread, need to discuss that within the project first (I'm not lead, but have requested a team meeting already) -- Kristian Fiskerstrand OpenPGP certificate reachable at hkp://pool.sks-keyservers.net fpr:94CB AFDD 3034 5109 5618 35AA 0B7F 8B60 E3ED FAE3
signature.asc
Description: OpenPGP digital signature