Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <7819606b-2330-4c50-9739-1ec8e9a1b804@ucar.edu>
Date: Tue, 16 Jun 2026 10:28:18 -0400
From: Prentice Bisbal <prentice@...r.edu>
To: oss-security@...ts.openwall.com
Subject: Re: Proposal: Add separate
 oss-security-vulnerability-reports mailing list (for AI vulnpocalypse)


On 6/15/26 1:56 PM, Alan Coopersmith wrote:
> On 6/8/26 16:46, David A. Wheeler wrote:
>> All: I propose that we create a *separate* mailing list, say
>> "oss-security-vulnerability-reports", for run-of-the-mill 
>> vulnerability reports
>> about open source software (OSS). Run-of-the-mill reports would then 
>> go there
>> and *not* to this mailing list "oss-security". This would leave 
>> *this* oss-security" mailing list
>> for general discussions about the topic of OSS security, including 
>> discussions about
>> specific publicly known vulnerabilities that are especially 
>> noteworthy in some way.
>> Tools that want the full flood could monitor 
>> "oss-security-vulnerability-reports".
>
> If it comes to the point we have to split the lists, I think it would 
> be easier
> to create a oss-security-discuss for the discussions than to get 
> dozens of
> projects to update their security advisory release process to send their
> advisories to a new list, or to rely on the projects to determine 
> which are
> newsworthy enough to go to the main list vs. your proposed new
> ...-vulnerability-reports list. 

I second this.

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.