On 7/6/16 7:30 AM, Kristian Fiskerstrand wrote:
> On 07/06/2016 01:15 PM, Anthony G. Basile wrote:
>> I'm also disappointed that no one else in the security team has
>> recommended any internal policing in response to this.  I maintain that
>> forced p.masking and version bumping should not be done by the security
>> team but passed to QA for review.  Only QA is mandated with such powers
>> by GLEP 48.
> 
> We're discussing this in another thread already (i.e possibly a GLEP for
> Security project), I'm discussing that as a member of security.
> 
> As for any internal policing outside of public policies it is done
> within the team and not on a public mailing list. The relevant public
> policies are:
> https://wiki.gentoo.org/wiki/Project:Security/GLSA_Coordinator_Guide
> https://www.gentoo.org/support/security/vulnerability-treatment-policy.html
> 
> But I agree these needs reviewing and codification in the form of a
> GLEP, but as said in the other thread, need to discuss that within the
> project first (I'm not lead, but have requested a team meeting already)
> 


I like this.  So let's make sure we have clear expectations and an
escalation process with review before we pull the p.mask with 30 days
till poof.

-- 
Anthony G. Basile, Ph.D.
Gentoo Linux Developer [Hardened]
E-Mail    : bluen...@gentoo.org
GnuPG FP  : 1FED FAD9 D82C 52A5 3BAB  DC79 9384 FA6E F52D 4BBA
GnuPG ID  : F52D4BBA

Reply via email to