Re: Security release procedures
From: Julian Foad <julianfoad_at_apache.org>
Date: Wed, 28 Aug 2019 12:41:45 +0100
This is not just theoretical. The next security issue has already landed
https://www.apache.org/security/committers
After dealing with the last pair of security fixes, I feel following
What could we reduce or eliminate from the process? Especially in the
* Drop the CVE? (steps 8, 15, 16)
For cases that are not looking like a very high severity, we could
Instead, on a case by case basis, we could choose to omit the CVE
* Drop the requirement to roll a release? (steps 12, 13, 14)
Under present procedures, rolling a release takes special private
Even the commit requires a little extra thought to come up with a
Instead we could release just the patch, initially. Then incorporate
- Julian
|
This is an archived mail posted to the Subversion Dev mailing list.
This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.