Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <0a21a870-8b0e-4e9a-b712-796c7dc8279a@gmail.com>
Date: Fri, 15 May 2026 05:03:25 -0400
From: Demi Marie Obenour <demiobenour@...il.com>
To: oss-security@...ts.openwall.com, Yves-Alexis Perez <corsac@...ian.org>
Subject: Re: Coordinated Disclosure in the LLM Age

On 5/15/26 04:49, Yves-Alexis Perez wrote:
> On Wed, 2026-04-29 at 19:22 +0200, Willy Tarreau wrote:
>> I'm increasingly doing that myself already, and predicted the death of
>> embargoes a serveral months ago. Now I just remove unneeded details from
>> commit messages, merging and issue releases to keep users protected.
> 
> Hey Willy,
> 
> Unfortunately that also has the side effects to hide security-relevant commits
> from downstream integrators and users. Not that we really have the time to dig
> each and every commit of each and every project (especially fast moving ones)
> but we definitely miss things here and there without a heads up.

I think the current upstream view is that one shouldn't bother
doing this and just upgrade to the next release.  Unfortunately,
nowadays one can't even wait for a release, so one must look through
individual commits.

I wish Linux adopted the Xen Project Security Policy, but that would
probably require a bunch of extra people.
-- 
Sincerely,
Demi Marie Obenour (she/her/hers)
Download attachment "OpenPGP_0xB288B55FFF9C22C1.asc" of type "application/pgp-keys" (7141 bytes)

Download attachment "OpenPGP_signature.asc" of type "application/pgp-signature" (834 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.