Re: Ports Secteam

2015-06-10 Thread Wesley Shields
As I've been unable to contribute to this team or to ports much lately I hereby 
request that I be removed from this team. I'd rather someone else who is more 
actively engaged take my spot.

-- WXS

> On Jun 8, 2015, at 7:31 PM, Xin Li  wrote:
> 
> Signed PGP part
> On 06/08/15 14:37, Robert Simmons wrote:
> > I'm sure that the reason these questions have not been answered is
> > simply because they may have gotten lost in the volume of traffic
> > on freebsd-ports. In the following thread, there are a number of
> > folks with enough passion to volunteer time to help with the Ports
> > Secteam, but we're having difficulty getting a few basic questions
> > answered.
> > https://lists.freebsd.org/pipermail/freebsd-ports/2015-May/099268.html
> >
> >  Here are the basic questions:
> >
> > Who are the members of the Ports Secteam?
> 
> Current members include the current security officers (who act as a
> fallback when needed and a contact for liaison for sensitive and
> embargoed information) and:
> 
> Eitan Adler (eadler@);
> Jason Helfman (jgh@);
> Martin Wilke (miwi@);
> Eygene Ryabinkin (rea@);
> Sofian Brabez (sbz@);
> Simon L. B. Nielsen (simon@, clusteradm@ liaison);
> Steve Wills (swills@);
> Wesley Shields (wxs@);
> Ryan Steinmetz (zi@);
> 
> > How does one join the Ports Secteam?
> 
> Per previous discussion with portmgr@, members are volunteers selected
> by the Security Officer from active ports committers who have made
> commits in the ports tree in the last 90 days.
> 
> Cheers,
> --
> Xin LI https://www.delphij.net/
> FreeBSD - The Power to Serve!   Live free or die
> 
> ___
> freebsd-security@freebsd.org mailing list
> http://lists.freebsd.org/mailman/listinfo/freebsd-security
> To unsubscribe, send any mail to "freebsd-security-unsubscr...@freebsd.org"



signature.asc
Description: Message signed with OpenPGP using GPGMail


Re: Ports Secteam

2015-06-10 Thread Eitan Adler
On 9 June 2015 at 22:30, Mark Felder  wrote:

>
> How do we make the ports-secteam effective again? Team members?
> Infrastructure? New documentation and procedures?

ports-secteam's scope has grown since it was created.  The team needs
new, active, members to be able to deal with the VuXML and quarterly
branch portion of its work.  We also need to creating tooling to make
this easier: for instance it would be really awesome to automatically
create VuXML entries from CVE/CPE data.

> However, I'm not sure
> "number of commits" is necessarily a valuable metric when considering
> candidates...

I agree.  I *am* active as a ports-security member: I monitor relevent
open & closed security lists for concerns that may affect FreeBSD.  In
addition I watch pkgng development for new security concerns.  That
said, I havn't committed to the ports tree very much lately.

-- 
Eitan Adler
___
freebsd-security@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscr...@freebsd.org"