Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20230915210906.GA22532@openwall.com>
Date: Fri, 15 Sep 2023 23:09:06 +0200
From: Solar Designer <solar@...nwall.com>
To: oss-security@...ts.openwall.com
Subject: Re: illumos (or at least danmcd) membership in the distros list

Hi Dan,

Your request looks good to me, except that this criterion:

On Wed, Sep 13, 2023 at 08:21:22PM +0000, Dan McDonald wrote:
> > Have a publicly verifiable track record, dating back at least 1 year and continuing to present day, of fixing security issues (including some that had been handled on (linux-)distros, meaning that membership would have been relevant to you) and releasing the fixes within 10 days (and preferably much less than that) of the issues being made public (if it takes you ages to fix an issue, your users wouldn't substantially benefit from the additional time, often around 7 days and sometimes up to 14 days, that list membership could give you)

is meant to be about the distro, not about you personally.

Alan Coopersmith also correctly pointed this out and made suggestions.

Can you show illumos fixing non-illumos-only security issues within days
after public disclosure, so that a few days of advance notice would have
made those fixes even quicker?

Thanks,

Alexander

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.