Establish contact with Nix and Guix teams a couple of days prior to release #20

Open
opened 2024-04-01 21:37:51 +00:00 by jade · 0 comments
Owner

This is a very late stage work item, but I am writing it down anyway. The reasons to do this are that we would like to establish a close security process so we avoid repeats of Puck's bug getting full-disclosure'd on Guix by our own carelessness as the reporters due to the lack of written security response process (!!). Additionally it would be preferable to have positive working relationships with both teams, even if there are many things we don't agree on.

This is a very late stage work item, but I am writing it down anyway. The reasons to do this are that we would like to establish a close security process so we avoid repeats of Puck's bug getting full-disclosure'd on Guix by our own carelessness as the reporters due to the lack of written security response process (!!). Additionally it would be preferable to have positive working relationships with both teams, even if there are many things we don't agree on.
jade added this to the Release engineering project 2024-04-01 21:37:51 +00:00
Sign in to join this conversation.
No labels
A-infra
A-matrix
No milestone
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: lix-project/meta#20
No description provided.