All of lore.kernel.org
 help / color / mirror / Atom feed
* [Formal Vote] Changes to Xen Project Security Vulnerability Process - Open until June 8th, 2015
@ 2015-06-01  9:36 Lars Kurth
  2015-06-01 17:59 ` Konrad Rzeszutek Wilk
                   ` (2 more replies)
  0 siblings, 3 replies; 11+ messages in thread
From: Lars Kurth @ 2015-06-01  9:36 UTC (permalink / raw)
  To: <xen-devel@lists.xen.org>, keir Fraser, Ian Jackson,
	Ian Campbell, Tim Deegan, Konrad Rzeszutek Wilk
  Cc: security, Major Hayden


[-- Attachment #1.1: Type: text/plain, Size: 1790 bytes --]

Hi,

in accordance with the project's governance, I would like to put the following text changes to a committer vote (committers are on the TO list). The discussion leading to the changes can be found at http://lists.xenproject.org/archives/html/xen-devel/2015-05/msg02881.html <http://lists.xenproject.org/archives/html/xen-devel/2015-05/msg02881.html>

Please vote +1, 0, -1 with explanation as usual. You can reply publicly or in private and I will collate results on the 9th.

Regards
Lars

Old text in http://www.xenproject.org/security-policy.html <http://www.xenproject.org/security-policy.html>
---
Specific process
...
4. Advisory pre-release: 

This occurs only if the advisory is embargoed (ie, the problem is not already public): 

As soon as our advisory is available, we will send it, including patches, to members of the Xen security pre-disclosure list. 

For more information about this list, see below. At this stage the advisory will be clearly marked with the embargo date.
---

Proposed text (this adds an additional paragraph, while  leaving the existing text as-is):
---
Specific process
...
4. Advisory pre-release: 

This occurs only if the advisory is embargoed (ie, the problem is not already public): 

As soon as our advisory is available, we will send it, including patches, to members of the Xen security pre-disclosure list. 

In the event that we do not have a patch available two working weeks before the disclosure date, we aim to send an advisory that reflects the current state of knowledge to the Xen security pre-disclosure list. An updated advisory will be published as soon as available.

For more information about this list, see below. At this stage the advisory will be clearly marked with the embargo date.
---

[-- Attachment #1.2: Type: text/html, Size: 2896 bytes --]

[-- Attachment #2: Type: text/plain, Size: 126 bytes --]

_______________________________________________
Xen-devel mailing list
Xen-devel@lists.xen.org
http://lists.xen.org/xen-devel

^ permalink raw reply	[flat|nested] 11+ messages in thread

end of thread, other threads:[~2015-06-09 12:09 UTC | newest]

Thread overview: 11+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2015-06-01  9:36 [Formal Vote] Changes to Xen Project Security Vulnerability Process - Open until June 8th, 2015 Lars Kurth
2015-06-01 17:59 ` Konrad Rzeszutek Wilk
2015-06-03  9:35 ` Ian Campbell
2015-06-05 11:32   ` Lars Kurth
2015-06-05 11:43     ` Ian Campbell
2015-06-08 10:08       ` Lars Kurth
2015-06-08 10:23         ` Jan Beulich
2015-06-08 10:40   ` Ian Jackson
2015-06-09 11:06     ` Lars Kurth
2015-06-09 12:09       ` Major Hayden
2015-06-04 13:21 ` Tim Deegan

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.