Consensus: Security Hall of Fame, Security issue attributions, NEWS, and Contribution Checklist.

Carlos O'Donell carlos@redhat.com
Wed Oct 21 17:57:00 GMT 2015


Community,

In April we adjusted MAINTAINERS->Contacting Maintainers to point
at the new security process[1][2].

I have now adjusted the Contribution Checklist to point to
the security process as the first step[3].

I have suggested that we add an attribution section to the NEWS
for each release to thank those people who report bugs via the
security process and for which those bugs are fixed in the release.
This suggestion is now in the Committers checklist[4].

Lastly I suggest that we have a "Security Hall of Fame" wiki page
where we collate the NEWS attributions at release time to allow
people to view their names.

The goal of these changes is to encourage security related issues
to go through the security process.

I am particularly interested in distribution maintainer feedback
on the process and if they would like anything changed.

Cheers,
Carlos.

[1] https://sourceware.org/glibc/wiki/Security%20Process
[2] https://sourceware.org/glibc/wiki/Security%20Exceptions
[3] https://sourceware.org/glibc/wiki/Contribution%20checklist#Security
[4] https://sourceware.org/glibc/wiki/Committer%20checklist#Update_The_NEWS_File



More information about the Libc-alpha mailing list