All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Daniel P. Berrangé" <berrange@redhat.com>
To: "Michael S. Tsirkin" <mst@redhat.com>
Cc: qemu-devel@nongnu.org,
	"Pierrick Bouvier" <pierrick.bouvier@oss.qualcomm.com>,
	"Alex Bennée" <alex.bennee@linaro.org>,
	"Mauro Matteo Cascella" <mcascell@redhat.com>,
	"Paolo Bonzini" <pbonzini@redhat.com>,
	"Thomas Huth" <thuth@redhat.com>
Subject: Re: [qemu-web RFC 0/3] switch to GitLab confidential issues for security disclosure
Date: Wed, 10 Jun 2026 12:07:30 +0100	[thread overview]
Message-ID: <ailFcly_pt6Job5Q@redhat.com> (raw)
In-Reply-To: <20260610062358-mutt-send-email-mst@kernel.org>

On Wed, Jun 10, 2026 at 06:28:34AM -0400, Michael S. Tsirkin wrote:
> On Thu, Jun 04, 2026 at 05:50:45PM +0100, Daniel P. Berrangé wrote:
> > I previously raised the idea of using GitLab issues for security
> > disclosures:
> > 
> >   https://lists.gnu.org/archive/html/qemu-devel/2026-05/msg04582.html
> 
> 
> Thanks a lot for posting this!
> 
> Do we want a special
> 
> .gitlab/issue_templates/security_bug.md
> 
> For this?
> 
> It can include guidance in a friendly way.

I'm on the fence about that. I was coming at this from the POV
that security issue disclosure and triage is effectively identical
to normal bug disclosure & triage. The only difference is that
a security issue is initially "confidential" until a maintainer
has sanity checked its severity. I don't think we need to prompt
for different types of information from the user, and even if we
did, it seems like we'll probably just get the  structured markdown
doc the LLM spits out that people have been emailing us.

Maybe it is sufficient to just link to the security.html page
from the existing issue template.


With regards,
Daniel
-- 
|: https://berrange.com       ~~        https://hachyderm.io/@berrange :|
|: https://libvirt.org          ~~          https://entangle-photo.org :|
|: https://pixelfed.art/berrange   ~~    https://fstop138.berrange.com :|



      reply	other threads:[~2026-06-10 11:07 UTC|newest]

Thread overview: 18+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-06-04 16:50 [qemu-web RFC 0/3] switch to GitLab confidential issues for security disclosure Daniel P. Berrangé
2026-06-04 16:50 ` [qemu-web RFC 1/3] contribute: reformat/restructure bug report guidance Daniel P. Berrangé
2026-06-08 13:13   ` Peter Maydell
2026-06-04 16:50 ` [qemu-web RFC 2/3] contribute: add automate tool disclosure to bug reporting Daniel P. Berrangé
2026-06-08 13:16   ` Peter Maydell
2026-06-10 10:29   ` Michael S. Tsirkin
2026-06-04 16:50 ` [qemu-web RFC 3/3] contribute: switch security process to gitlab confidential issues Daniel P. Berrangé
2026-06-08 13:39   ` Peter Maydell
2026-06-10 10:22     ` Michael S. Tsirkin
2026-06-10  8:14   ` Thomas Huth
2026-06-10 10:18   ` Michael S. Tsirkin
2026-06-10 11:02     ` Daniel P. Berrangé
2026-06-10 11:06       ` Michael S. Tsirkin
2026-06-10 11:10         ` Daniel P. Berrangé
2026-06-10 11:20           ` Michael S. Tsirkin
2026-06-08 16:10 ` [qemu-web RFC 0/3] switch to GitLab confidential issues for security disclosure Mauro Matteo Cascella
2026-06-10 10:28 ` Michael S. Tsirkin
2026-06-10 11:07   ` Daniel P. Berrangé [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=ailFcly_pt6Job5Q@redhat.com \
    --to=berrange@redhat.com \
    --cc=alex.bennee@linaro.org \
    --cc=mcascell@redhat.com \
    --cc=mst@redhat.com \
    --cc=pbonzini@redhat.com \
    --cc=pierrick.bouvier@oss.qualcomm.com \
    --cc=qemu-devel@nongnu.org \
    --cc=thuth@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.