> + * The maintainer(s) will develop and/or review patch(es) > + for the issue privately, optionally attaching work in > + progress fixes to the GitLab issues.
attaching how? how do i ask reported to test the fix? was easy in the email flow. > All patches must > + include the issue URL in the commit message(s). you mean the commit message of the patches I presume? there's no commit at that point. > The > + **"Workflow::In Progress"** label should be assigned when > + a maintainer starts working on a fix. That's a bit heavy, and what is "working" anyway. It's an issue tracker not a planning app. Don't try to make it one. > + * When a CVE is allocated, it must be recorded as a comment on > + the GitLab issue, and the **"CVE::Required"** label replaced by > + the **"CVE::Assigned"** label. Recorded as a comment how exactly, in what format? > + * The maintainer(s) will update the commit message(s) what does it mean to "update the commit message"? > to include > + the assigned CVE and issue URL. If multiple commits are required > + to fix an issue the CVE must be included in the final commit in > + the series, and may optionally be included in all prior commits. And here, included in what format?
