Skip to content

updated expectation management on sec issues#437

Open
DaanHoogland wants to merge 1 commit into
staging-sitefrom
sec-update
Open

updated expectation management on sec issues#437
DaanHoogland wants to merge 1 commit into
staging-sitefrom
sec-update

Conversation

@DaanHoogland
Copy link
Copy Markdown
Contributor

No description provided.

Comment thread src/pages/security.md
validated, it will still take time to fix the issue. The amount of
time depends on the availability of volunteers and number people
involved that have a stake in the issue. In later years it has turned
out to take up to six months, from notification to public announcement
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

do we need to be specific here? I don't think we need to mention this whole sentence at all

Comment thread src/pages/security.md
Comment on lines +44 to +46
validated, it will still take time to fix the issue. The amount of
time depends on the availability of volunteers and number people
involved that have a stake in the issue. In later years it has turned
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It might make sense to mention that the round-trip time also depends on the severity of the issue? Hopefully severe issues won't be open for six months ;)

Comment thread src/pages/security.md
Comment on lines +47 to +48
out to take up to six months, from notification to public announcement
of the vulnerability, due to parallel work on multiple issues. During
Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
out to take up to six months, from notification to public announcement
of the vulnerability, due to parallel work on multiple issues. During
out to take up more and more time from notification to public announcement
of the vulnerability, due to parallel work on multiple issues. During

@borisstoyanov @raboof ?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants