Re: Renaming repos and security concerns

2019-02-10 Thread Craig Russell
Hi Justin, > On Feb 9, 2019, at 8:16 PM, Justin Mclean wrote: > > Hi, > >> As I mentioned else-thread, I think the date should be the date the >> repository is moved to the Incubator, not the date the project is voted into >> the incubator. > > This seams reasonable but that not what has be

Re: Renaming repos and security concerns

2019-02-09 Thread Justin Mclean
Hi, > As I mentioned else-thread, I think the date should be the date the > repository is moved to the Incubator, not the date the project is voted into > the incubator. This seams reasonable but that not what has been happening in most cases, the repo get transferred and then unapproved rele

Re: Renaming repos and security concerns

2019-02-09 Thread Craig Russell
> On Feb 8, 2019, at 2:59 PM, Justin Mclean wrote: > > Hi, > >> We need to make sure that pre-Apache releases whether source or binary are >> treated in a fair way. > > As long are they are not in after the date of incubation and clearly marked I > see no issues. As I mentioned else-thread

Re: Renaming repos and security concerns

2019-02-09 Thread Greg Stein
Hehe... I think she just said "patches welcome" šŸ˜‹ On Sat, Feb 9, 2019, 08:19 Myrle Krantz I have no objections to you editing that into it. I do however think it's > important to explain the reasons for the rules together with the rules. > > Please note that I've mentioned legal jeopardy, so if

Re: Renaming repos and security concerns

2019-02-09 Thread Myrle Krantz
I have no objections to you editing that into it. I do however think it's important to explain the reasons for the rules together with the rules. Please note that I've mentioned legal jeopardy, so if you're going to "strengthen" the language you may need to delete existing text to avoid redundanc

Re: Renaming repos and security concerns

2019-02-09 Thread Justin Mclean
Hi, > Thank you. I've corrected some typos, and then added a motivation > section. Questions/comments/suggestions, as always, welcome. Thanks for edits but I think you missed the main reason, it's mostly about the legal umbrella and protection we give our (P)PMCā€™s. If they do something outsid

Re: Renaming repos and security concerns

2019-02-09 Thread Myrle Krantz
Thank you. I've corrected some typos, and then added a motivation section. Questions/comments/suggestions, as always, welcome. Best Regards, Myrle On Fri, Feb 8, 2019 at 11:59 PM Justin Mclean wrote: > Hi, > > > We need to make sure that pre-Apache releases whether source or binary > are trea

Re: Renaming repos and security concerns

2019-02-08 Thread Justin Mclean
Hi, > We need to make sure that pre-Apache releases whether source or binary are > treated in a fair way. As long are they are not in after the date of incubation and clearly marked I see no issues. > An Ć¼ber-comment - letā€™s be exceedingly careful with time limits for > ā€œcomplianceā€. What do

Re: Renaming repos and security concerns

2019-02-08 Thread Dave Fisher
> On Feb 8, 2019, at 1:36 PM, Justin Mclean wrote: > > HI, > > In the thread on guidelines for distributions I suggested some common naming > to help with trademarks, branding and be in line with release policy. > > There's a possible security issue here, as people could (in theory) take ov

Renaming repos and security concerns

2019-02-08 Thread Justin Mclean
HI, In the thread on guidelines for distributions I suggested some common naming to help with trademarks, branding and be in line with release policy. There's a possible security issue here, as people could (in theory) take over the old name and put something malicious there if the old name was