On 7/6/16 7:30 AM, Kristian Fiskerstrand wrote: > On 07/06/2016 01:15 PM, Anthony G. Basile wrote: >> I'm also disappointed that no one else in the security team has >> recommended any internal policing in response to this. I maintain that >> forced p.masking and version bumping should not be done by the security >> team but passed to QA for review. Only QA is mandated with such powers >> by GLEP 48. > > We're discussing this in another thread already (i.e possibly a GLEP for > Security project), I'm discussing that as a member of security. > > As for any internal policing outside of public policies it is done > within the team and not on a public mailing list. The relevant public > policies are: > https://wiki.gentoo.org/wiki/Project:Security/GLSA_Coordinator_Guide > https://www.gentoo.org/support/security/vulnerability-treatment-policy.html > > But I agree these needs reviewing and codification in the form of a > GLEP, but as said in the other thread, need to discuss that within the > project first (I'm not lead, but have requested a team meeting already) >
I like this. So let's make sure we have clear expectations and an escalation process with review before we pull the p.mask with 30 days till poof. -- Anthony G. Basile, Ph.D. Gentoo Linux Developer [Hardened] E-Mail : bluen...@gentoo.org GnuPG FP : 1FED FAD9 D82C 52A5 3BAB DC79 9384 FA6E F52D 4BBA GnuPG ID : F52D4BBA