From: Junio C Hamano <gitster@pobox.com>
To: "Julia Ramer via GitGitGadget" <gitgitgadget@gmail.com>
Cc: git@vger.kernel.org, git-security@googlegroups.com,
Johannes Schindelin <Johannes.Schindelin@gmx.de>,
Julia Ramer <prplr@github.com>,
Keanen Wold <keanenwold@github.com>,
Veronica Giaudrone <veronica.Giaudrone@microsoft.com>,
Bri Brothers <brbrot@microsoft.com>,
Julia Ramer <gitprplr@gmail.com>
Subject: Re: [PATCH v2] embargoed releases: also describe the git-security list and the process
Date: Wed, 19 Oct 2022 15:01:22 -0700 [thread overview]
Message-ID: <xmqq4jvzpj65.fsf@gitster.g> (raw)
In-Reply-To: <xmqqa65rr6g1.fsf@gitster.g> (Junio C. Hamano's message of "Wed, 19 Oct 2022 11:53:18 -0700")
Junio C Hamano <gitster@pobox.com> writes:
> -- Within a couple of days, someone from the core Git team responds with an
> - initial assessment of the bug’s severity.
> +- Within a couple of days, someone from the core Git team, including
> + the Git maintainer, responds with an initial assessment of the
> + bug’s severity.
The "including" here looks even less clear. Does somebody other
than me and I should respond? That is not what I wanted to say.
Hence ...
> -- Other core developers - including the Git maintainer - chime in.
> +- Other core developers chime in.
... I wonder if it would be better to consolidate the above two into
one bullet point, e.g.
- The security-list members start a discussion to give an initial
assessment of the severity of potential vulnerability reported.
We aspire to do so within a few days.
> -- The Git for Windows, Git for macOS, BSD, Debian, etc maintainers prepares the
> +- The Git for Windows, Git for macOS, BSD, Debian, etc. maintainers prepares the
> corresponding release artifacts, based on the tags created that have been
> prepared by the Git maintainer.
"prepares" -> "prepare".
> - Less than a week before the release, a mail with the relevant information is
> sent to <distros@vs.openwall.org> (see below), a list used to pre-announce
> embargoed releases of open source projects to the stakeholders of all major
> - Linux distributions. This includes a Git bundle of the tagged version(s), but
> - no further specifics of the vulnerability.
> + distributions of Linux as well as other OSes. This includes a Git bundle
> + of the tagged version(s), but no further specifics of the vulnerability.
The bundle contains enough information to recreate these tagged
versions under embargo, hence the release notes for these releases
that discloses the vulnerability. Perhaps drop "but no further..."?
next prev parent reply other threads:[~2022-10-19 22:01 UTC|newest]
Thread overview: 24+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-09-01 22:39 [PATCH] embargoed releases: also describe the git-security list and the process Julia Ramer via GitGitGadget
2022-09-02 17:24 ` Junio C Hamano
2022-09-27 22:56 ` Julia Ramer
2022-09-28 17:12 ` Junio C Hamano
2022-10-18 20:43 ` Julia Ramer
2022-10-19 15:47 ` Junio C Hamano
2022-09-02 18:59 ` Junio C Hamano
2022-09-03 9:29 ` Johannes Schindelin
2022-09-05 20:28 ` Junio C Hamano
2022-10-19 1:16 ` [PATCH v2] " Julia Ramer via GitGitGadget
2022-10-19 18:53 ` Junio C Hamano
2022-10-19 21:22 ` Taylor Blau
2022-10-19 22:01 ` Junio C Hamano [this message]
2022-10-19 21:15 ` Taylor Blau
2022-10-19 21:50 ` Junio C Hamano
2022-10-20 17:06 ` Taylor Blau
2022-10-21 7:41 ` [PATCH v3] " Julia Ramer via GitGitGadget
2022-10-21 16:42 ` Junio C Hamano
2022-10-24 20:18 ` Julia Ramer
2022-10-24 22:56 ` Junio C Hamano
2022-10-22 0:11 ` Taylor Blau
2022-10-24 20:19 ` Julia Ramer
2022-10-24 22:07 ` [PATCH v4] " Julia Ramer via GitGitGadget
2022-10-24 23:08 ` Junio C Hamano
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=xmqq4jvzpj65.fsf@gitster.g \
--to=gitster@pobox.com \
--cc=Johannes.Schindelin@gmx.de \
--cc=brbrot@microsoft.com \
--cc=git-security@googlegroups.com \
--cc=git@vger.kernel.org \
--cc=gitgitgadget@gmail.com \
--cc=gitprplr@gmail.com \
--cc=keanenwold@github.com \
--cc=prplr@github.com \
--cc=veronica.Giaudrone@microsoft.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).