Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20170522234408.GA7465@wopr>
Date: Mon, 22 May 2017 16:44:08 -0700
From: Kurt H Maier <khm@...ops.net>
To: oss-security@...ts.openwall.com
Subject: Re: How to request a CVE for open source projects

On Mon, May 22, 2017 at 03:13:42PM -0600, Kurt Seifried wrote:
> Well actually they can. Why do you think we (DWF) have an extensible Json format with the data hosted in git? Hint: so people can contribute.

Is it the opaque Google Docs form that fosters contribution, or the
gatekept pull-request process requiring a Github account that fosters
contribution?

At what point in the DWF process is third-party input expected to occur?
The matter is not addressed in the documentation repository.  Feel free 
to mail me offlist if the answers would induce excessive cognitive 
dissonance.

khm

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.