Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <2026051536-gatherer-excluding-f6ff@gregkh>
Date: Fri, 15 May 2026 11:27:00 +0200
From: Greg KH <greg@...ah.com>
To: oss-security@...ts.openwall.com
Subject: Re: Coordinated Disclosure in the LLM Age

On Fri, May 15, 2026 at 10:49:34AM +0200, Yves-Alexis Perez wrote:
> On Wed, 2026-04-29 at 19:22 +0200, Willy Tarreau wrote:
> > I'm increasingly doing that myself already, and predicted the death of
> > embargoes a serveral months ago. Now I just remove unneeded details from
> > commit messages, merging and issue releases to keep users protected.
> 
> Hey Willy,
> 
> Unfortunately that also has the side effects to hide security-relevant commits
> from downstream integrators and users. Not that we really have the time to dig
> each and every commit of each and every project (especially fast moving ones)
> but we definitely miss things here and there without a heads up.

With the advent of the reporting requirements of the EU CRA law, as of
the end of next year, all projects will have to be reporting their
"security bugfixes" to the EU, so you will be able to go off of that
feed.

Although that is a 18 months away, but something to look forward to :)

thanks,

greg k-h

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.