oss-sec mailing list archives
Re: Gentoo's "contributing back" linux-distros tasks
From: Solar Designer <solar () openwall com>
Date: Tue, 2 Feb 2021 21:44:20 +0100
On Tue, Feb 02, 2021 at 10:48:30AM -0800, Anthony Liguori wrote:
Anthony Liguori <aliguori () amzn com> writes:Solar Designer <solar () openwall com> writes:13. Keep track of per-report and per-issue handling and disclosure timelines (at least times of notification of the private list and of actual public disclosure), at regular intervals produce and share statistics (most notably, the average embargo duration) as well as the raw data (except on issues that are still under embargo) by posting to oss-security - primary: Gentoo, backup: Amazon and we saw some contributions from Gentoo on these, most notable being their work on the statistics (task 13 above): https://oss-security.openwall.org/wiki/mailing-lists/distros/stats Unfortunately, the last update of these statistics ("Last modified: 2019/10/15 01:52 by kristianf") is also when the contributions ceased.As part of planning on getting this going again, I want to just review the cadence and update duration. I think this is easiest to do on the 15th of every month for the previous month. As example, on 2/15, we would post the statistics for February. Since the maximum embargo duration is 2-weeks, this would not disclose any embargoed information. Does this seem reasonable?
You mean for January. Yes. Occasionally there will be an issue that should have already been made public but actually wasn't yet, or not on oss-security. An issue where others responsible failed to ensure its timely and proper public disclosure. In such cases, I expect the person working on the statistics task would notice that and help ensure this issue is made public without further delay and properly (such as by pinging others to do it), and only then will post the statistics including the issue. In fact, if the statistics task is correctly worked on, such issues with issues are impossible not to notice: every issue in the published raw data for the statistics should have its corresponding oss-security posting referenced. So you'd notice when trying to fill in that field. Alexander
Current thread:
- Re: Gentoo's "contributing back" linux-distros tasks Solar Designer (Jan 10)
- <Possible follow-ups>
- Re: Gentoo's "contributing back" linux-distros tasks Solar Designer (Jan 10)
- Re: Gentoo's "contributing back" linux-distros tasks Thomas Deutschmann (Jan 11)
- Re: Gentoo's "contributing back" linux-distros tasks Solar Designer (Jan 12)
- RE: Gentoo's "contributing back" linux-distros tasks Anthony Liguori (Jan 12)
- Re: Gentoo's "contributing back" linux-distros tasks Thomas Deutschmann (Jan 11)
- Re: Gentoo's "contributing back" linux-distros tasks Anthony Liguori (Jan 11)
- Re: Gentoo's "contributing back" linux-distros tasks Anthony Liguori (Feb 02)
- Re: Gentoo's "contributing back" linux-distros tasks Solar Designer (Feb 02)