oss-sec mailing list archives

Re: CoreOS membership to linux-distros (updated)


From: Solar Designer <solar () openwall com>
Date: Fri, 21 Jul 2017 15:26:47 +0200

On Tue, Jul 18, 2017 at 02:56:23PM -0700, Euan Kemp wrote:
I???ve listed each criterion and why I think we, the Container Linux team
at CoreOS, qualify.

I intend to add CoreOS to linux-distros in early August unless there are
any well-reasoned objections by then.

Based on your previous messages, it sounds like it???s expected for us to
inherit 'primary' for the administrative tasks of:
1. Promptly review new issue reports for meeting the list's requirements and confirm receipt of the report and, 
when necessary, inform the reporter of any issues with their report (e.g., obviously not actionable by the distros) 
and request and/or propose any required yet missing information (most notably, a tentative public disclosure date) 
- primary: CloudLinux, backup: vacant
2. If the proposed public disclosure date is not within list policy, insist on getting this corrected and propose a 
suitable earlier date - primary: CloudLinux, backup: vacant

Right.  CloudLinux - please get ready to pick up some other task(s).

I???ll also volunteer us for the administrative task of:
6. If multiple issues are reported at once, see if any of them can reasonably be made public sooner than the rest, 
and if so help untangle them and stay on top of their disclosure process

We???ll be happy to be on the lookout for possible conflation of issues
and kick off discussion if we think something can be broken up.

This works.  Thanks.

We???ll provide relevant GPG keys separately if our membership is accepted.

Kees Cook can vouch for Brandon Philips (both on cc).

Please feel free to provide the GPG keys to me off-list.  Also, Brandon
should vouch for the rest of your team (again, off-list to me is OK).

Alexander


Current thread: