From: "Daniel P. Berrangé" <berrange@redhat.com>
To: P J P <ppandit@redhat.com>
Cc: Michael Tsirkin <mtsirkin@redhat.com>, qemu-devel@nongnu.org
Subject: Re: About 'qemu-security' list subscription process
Date: Fri, 15 Jan 2021 18:10:29 +0000 [thread overview]
Message-ID: <20210115181029.GY1692978@redhat.com> (raw)
In-Reply-To: <r95p856o-o5r3-1r88-p675-2111r17p7794@erqung.pbz>
On Thu, Jan 14, 2021 at 07:33:32PM +0530, P J P wrote:
> Hello,
>
> * We have received quite a few subscription requests for the 'qemu-security'
> list in the last few weeks. Majority of them are rejected because we could
> not identify the user from merely their email-id.
>
> * I have requested them to send a subscription request email with a 'Self
> Introduction' to the list.
>
> * However, some of the subscribers are familiar from the
> qemu-devel/oss-security mailing lists. And some are corporate emails like
> <secalert@rh.c>
>
> * One of the request is pending (3+) votes/acks for OR against member
> subscription.
>
> How do we handle these requests?
I believe we want to keep the membership of qemu-security reasonably
small. Primarily people who can commit to helping with the initial
triage to identify which specific subsystem maintainers to pull in.
In addition major consumers of QEMU with whom we need to coordinate
choice of disclosure date for embargoed images.
There is obviously a danger to the project if we mistakenly allow
membership from someone who is not acting in interests in the QEMU
project, so I think the bar needs to be reasonably high. IOW ideally
there should be some web of trust whereby some existing member(s)
knows the person/entity who is requesting acces. Other cases would
have to be evaluated case-by-case basis.
Regards,
Daniel
--
|: https://berrange.com -o- https://www.flickr.com/photos/dberrange :|
|: https://libvirt.org -o- https://fstop138.berrange.com :|
|: https://entangle-photo.org -o- https://www.instagram.com/dberrange :|
next prev parent reply other threads:[~2021-01-15 18:12 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2021-01-14 14:03 About 'qemu-security' list subscription process P J P
2021-01-15 18:10 ` Daniel P. Berrangé [this message]
2021-01-22 13:13 ` P J P
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20210115181029.GY1692978@redhat.com \
--to=berrange@redhat.com \
--cc=mtsirkin@redhat.com \
--cc=ppandit@redhat.com \
--cc=qemu-devel@nongnu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).