Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Fri, 21 Jul 2017 15:26:47 +0200
From: Solar Designer <solar@...nwall.com>
To: Euan Kemp <euan.kemp@...eos.com>
Cc: oss-security@...ts.openwall.com, keescook@...gle.com,
	Brandon Philips <brandon.philips@...eos.com>,
	Alex Crawford <alex.crawford@...eos.com>
Subject: Re: CoreOS membership to linux-distros (updated)

On Tue, Jul 18, 2017 at 02:56:23PM -0700, Euan Kemp wrote:
> I???ve listed each criterion and why I think we, the Container Linux team
> at CoreOS, qualify.

I intend to add CoreOS to linux-distros in early August unless there are
any well-reasoned objections by then.

> Based on your previous messages, it sounds like it???s expected for us to
> inherit 'primary' for the administrative tasks of:
> > 1. Promptly review new issue reports for meeting the list's requirements and confirm receipt of the report and, when necessary, inform the reporter of any issues with their report (e.g., obviously not actionable by the distros) and request and/or propose any required yet missing information (most notably, a tentative public disclosure date) - primary: CloudLinux, backup: vacant
> > 2. If the proposed public disclosure date is not within list policy, insist on getting this corrected and propose a suitable earlier date - primary: CloudLinux, backup: vacant

Right.  CloudLinux - please get ready to pick up some other task(s).

> I???ll also volunteer us for the administrative task of:
> > 6. If multiple issues are reported at once, see if any of them can reasonably be made public sooner than the rest, and if so help untangle them and stay on top of their disclosure process
> 
> We???ll be happy to be on the lookout for possible conflation of issues
> and kick off discussion if we think something can be broken up.

This works.  Thanks.

> We???ll provide relevant GPG keys separately if our membership is accepted.

> Kees Cook can vouch for Brandon Philips (both on cc).

Please feel free to provide the GPG keys to me off-list.  Also, Brandon
should vouch for the rest of your team (again, off-list to me is OK).

Alexander

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.