oss-sec mailing list archives

Re: illumos (or at least danmcd) membership in the distros list


From: Solar Designer <solar () openwall com>
Date: Thu, 14 Sep 2023 17:14:03 +0200

On Thu, Sep 14, 2023 at 10:42:19AM -0400, Demi Marie Obenour wrote:
On Wed, Sep 13, 2023 at 08:21:22PM +0000, Dan McDonald wrote:
For now, I would like to add myself:  danmcd () mnx io.

Would security () illumos org be a better choice?

No.  One of the differences of (linux-)distros from its predecessor
vendor-sec is that we don't subscribe any exploder addresses - we only
subscribe individuals.  Some distro security teams can be rather large,
with not everyone in there needing direct (linux-)distros subscription.
Also, by far not every issue is relevant to every distro.  So the
distro's individual representatives on (linux-)distros are supposed to
share only relevant information with others on their teams.

That said, the membership is for the distro, not for the individuals.
The Subject line here is confused about that.  The difference is in what
uses of information are allowed (only for the distro's security) and in
conditions for staying subscribed (only while requested by the distro's
leadership and only as needed for the distro's security).

Alexander


Current thread: