|
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] Re: [Xen-devel] [PATCH RFC] Make all public hosting providers eligible for the pre-disclosure list
On 03/12/12 17:26, Ian Campbell wrote: On Mon, 2012-12-03 at 17:12 +0000, George Dunlap wrote: I was going to say that if they're not informed, there may be a longer turn-around time; but providers on the list are explicitly allowed to say that there *is* a vulnerability, and *when* the disclosure is scheduled to be, so if it's just a matter of making the same bits available that Debian has made available, it shouldn't be too long for those who are prepared. But how much extra work would you need to do to qualify you for the list? Suppose there's a derivative with a single additional patch -- that will still require pulling in the source, potentially porting the patch, doing a re-build, and some basic re-testing -- that whole thing could take a day even for a well-funded project. If the criteria is so small, and so easy to qualify (just re-build the package basically), I'm not sure it's so useful to mention it. I went looking for the linux-distros list inclusion criteria, in the hopes we could just piggy back off that, but I can't find it right now. I've got a draft I think is helpful; I'll send a v2 and people can see what they think of it. -George _______________________________________________ Xen-devel mailing list Xen-devel@xxxxxxxxxxxxx http://lists.xen.org/xen-devel
|
![]() |
Lists.xenproject.org is hosted with RackSpace, monitoring our |