GNU C Library as its own CNA?
Siddhesh Poyarekar
siddhesh@gotplt.org
Fri Jul 28 16:11:33 GMT 2023
On 2023-07-28 12:09, Florian Weimer wrote:
> * Siddhesh Poyarekar:
>
>> At the outset, we'll need to have broad agreement on the following:
>>
>> 1. How should users submit issues? We would need an independent,
>> private mailing list, possibly one that can also do PGP for users to
>> report security issues.
>>
>> 2. Identify a group of people who ought to be on that list. A
>> starting group could be a cross section of named maintainers from
>> various distributions and FSF stewards but we probably need a way to
>> make sure that the group is inclusive without being too broad.
>>
>> 3. A formal representation to the root CNA, i.e. Red Hat. We would
>> need a group of volunteers that would be willing to step in as signees
>> for this. I'm in, but I can't do it alone and would need more
>> volunteers; it could perhaps be the same set of people who would be
>> part of the initial security team in (2).
>
> I think the CNA rules sort of assume that a CNA issues security
> advisories:
>
> <https://www.cve.org/ResourcesSupport/AllResources/CNARules>
>
> So we'd have to start doing that, too.
Yes, and we would have to honour some SLAs for the entire process, from
acknowledging CVEs to making them public. I reckon we could still rely
on some help from distro maintainers for some of this coordination.
Sid
More information about the Libc-alpha
mailing list