oss-sec mailing list archives
Re: linux-distros list membership application - CIQ Rocky Linux Security Team
From: Morten Linderud <foxboron () archlinux org>
Date: Tue, 17 Oct 2023 08:00:36 +0200
On Fri, Oct 13, 2023 at 11:19:18PM -0400, Neal Gompa wrote:
On Fri, Oct 13, 2023 at 8:07 PM Martin Hecht <martin.hecht () hlrs de> wrote:Well, assuming there was a security team in these projects able to obey the embargo regulations, wouldn't they have tried to join? But, nevertheless, what is the relation of the organizational structure of these projects with the current application of CIQ/Rocky, after all?The point I'm making is that SIGs do not count because they cannot obey embargo regulations. No open project or community project can do that without having some mechanism for private controls, which is antithetical to the community process. They fundamentally are ineligible to join because they cannot keep anything secret.
This just seems like a personal opinion projected onto the relevant projects though. There is nothing preventing you from getting access to patches and distributing them to relevant package maintainers for preperation under an embargo. Evidently there are three atleast 3 community distros already participating on the linux-distros list, namely Debian, Arch and Gentoo. So while Fedora might not have any way to distribute patches, please don't infer that this applies to all community distros. We do this in Arch Linux, and I've personally handeled several embargos as a community project. https://oss-security.openwall.org/wiki/mailing-lists/distros A relevant piece of information is also the well-written Gentoo Pre-Release Disclosure Agreement they have with their package maintainers. https://wiki.gentoo.org/wiki/Project:Security/Pre-Release-Disclosure Personally my impression of Fedora after trying to pay attention to their security meetings and general security planning, all of this seems to be handeled by Red Hat. So Fedora might not have any need to join the Linux distros list themselves. -- Morten Linderud PGP: 9C02FF419FECBE16
Attachment:
signature.asc
Description:
Current thread:
- linux-distros list membership application - CIQ Rocky Linux Security Team Solar Designer (Oct 01)
- Re: linux-distros list membership application - CIQ Rocky Linux Security Team Solar Designer (Oct 11)
- Re: linux-distros list membership application - CIQ Rocky Linux Security Team Vegard Nossum (Oct 12)
- Re: linux-distros list membership application - CIQ Rocky Linux Security Team Neal Gompa (Oct 13)
- Re: linux-distros list membership application - CIQ Rocky Linux Security Team Martin Hecht (Oct 13)
- Re: linux-distros list membership application - CIQ Rocky Linux Security Team Neal Gompa (Oct 14)
- Re: linux-distros list membership application - CIQ Rocky Linux Security Team Jeremy Stanley (Oct 14)
- Re: linux-distros list membership application - CIQ Rocky Linux Security Team Solar Designer (Oct 14)
- Re: linux-distros list membership application - CIQ Rocky Linux Security Team Morten Linderud (Oct 17)
- Re: linux-distros list membership application - CIQ Rocky Linux Security Team Solar Designer (Oct 17)
- Re: linux-distros list membership application - CIQ Rocky Linux Security Team Solar Designer (Oct 11)
- Re: linux-distros list membership application - CIQ Rocky Linux Security Team Solar Designer (Oct 14)