Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <4386b3433ad85d4bb93e1ca2a07088d2b83bb23e.camel@debian.org>
Date: Fri, 15 May 2026 10:49:34 +0200
From: Yves-Alexis Perez <corsac@...ian.org>
To: oss-security@...ts.openwall.com
Subject: Re: Coordinated Disclosure in the LLM Age

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

On Wed, 2026-04-29 at 19:22 +0200, Willy Tarreau wrote:
> I'm increasingly doing that myself already, and predicted the death of
> embargoes a serveral months ago. Now I just remove unneeded details from
> commit messages, merging and issue releases to keep users protected.

Hey Willy,

Unfortunately that also has the side effects to hide security-relevant commits
from downstream integrators and users. Not that we really have the time to dig
each and every commit of each and every project (especially fast moving ones)
but we definitely miss things here and there without a heads up.
- -- 
Yves-Alexis
-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEE8vi34Qgfo83x35gF3rYcyPpXRFsFAmoG3h4ACgkQ3rYcyPpX
RFu74wf9GSMYyetIEEW6B/GFZIcdTClqHMJP7UC3IE6lXqE1OF2Uxz1BcqDZ4XYX
owSxbzTx6V7Qo++gjQuUDrWmkLppq8lfnDdi4tiYZ6KhhwGD3nOMjx4J7MOId5GX
MJ7f/651CwPOJcPb29qzdybs3Zm8trz5C2k96D4ewNgmLrgHNf4kAJCrgLxhzZSw
/dP9YAHKReyfa//OPBwf4qoT31AlZ4aOW1LuozW8ws/gAxURYYW0CyIKZ0F3+YbR
vIWp5hU6zmIekaai/9pSYbIrZm6nxYnxcmiPSg5nL7YunNhY36+p8tD2xf/pqJYb
D6KJmbc9AYYYp4pf1KEOqVKjZnsefw==
=mSVB
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.