This Bugzilla instance is deprecated, and most Eclipse projects now use GitHub or Eclipse GitLab. Please see the deprecation plan for details.
Bug 276585 - eclipse-rt-security mailing list
Summary: eclipse-rt-security mailing list
Status: CLOSED WONTFIX
Alias: None
Product: Community
Classification: Eclipse Foundation
Component: MailingLists (show other bugs)
Version: unspecified   Edit
Hardware: PC Mac OS X - Carbon (unsup.)
: P3 normal (vote)
Target Milestone: ---   Edit
Assignee: Eclipse Webmaster CLA
QA Contact:
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2009-05-15 20:49 EDT by Jesse McConnell CLA
Modified: 2010-12-21 10:44 EST (History)
3 users (show)

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jesse McConnell CLA 2009-05-15 20:49:28 EDT
Many people in the RT projects have heard of this, but this is the request to get this mailing list created.

Initial members should be all project leads for the RT project, but if you just want to make the list I'll follow up with the various groups to make sure everyone gets on it.

The impetus behind this is that jetty has always had a mechanism to notify the community of security related issues and it was thought that all projects in RT ought to be linked up for getting this information out amongst the key stakeholders in the RT community.

cc'ing greg, my jetty project lead so he knows the request as well

cheers
Comment 1 Denis Roy CLA 2009-05-27 15:22:35 EDT
So is this a Jetty-only list, or for RT as a whole?
Comment 2 Denis Roy CLA 2009-11-24 10:50:47 EST
Closing as invalid.  If you still need this list, please provide the info requested in comment 1 and we'll make it happen.
Comment 3 Jesse McConnell CLA 2009-11-24 11:08:18 EST
RT as a whole I would think as this is something that the rt group as a whole would be concerned about, jetty can't be the only one that has to worry about security vulnerabilities

reopenning and adding jeff mcaffer as a watcher and asking him if we can put this on the agenda for the next rt pmc meeting.

cheers
jesse
Comment 4 Jesse McConnell CLA 2009-12-02 16:27:15 EST
We reviewed this issue in the latest RT-PMC call

Notes are here:

http://wiki.eclipse.org/RT/meetings/PMC_Minutes_091202

this would be a closed list a la the board votes lists and other of that ilk...
Comment 5 Denis Roy CLA 2009-12-02 16:49:56 EST
(In reply to comment #4)
> this would be a closed list

One thing to consider is that Bugzilla already has an option for private (closed) bugs specifically for this purpose.  As I see it, it is enabled for Jetty.

The typical workflow here is that someone (on your team, or a user) reports an 'open' bug saying 'I found a security issue'.  You would then mark the bug as private, enabling discussion only between Eclipse Committers, the bug reporter, and anyone else in the CC list.

Once the issue is resolved, patches are created, advisories are sent, you could (and eventually should) open the bug to the general public.

This option is more flexible than a mailing list, since you can easily add 'outsiders' to the CC list so that they can participate.

I would encourage you to try the option if you think it could suit your needs.  If not, we can go ahead and create a mailing list.
Comment 6 Jeff McAffer CLA 2009-12-07 21:00:23 EST
Sorry I missed that call.  I agree with Denis that we should try the Bugzilla approach but have two questions:
-  how to I get notified of a new security issue
-  who is approved to look at security issues

BTW, Jesse, feel free to edit the wiki at any time to add agenda topics for the RT PMC calls
Comment 7 Denis Roy CLA 2009-12-10 09:54:55 EST
> -  how to I get notified of a new security issue
> -  who is approved to look at security issues


The typical workflow is that someone (on your team, or a user) opens a plain bug saying 'I found a security issue' with no other details.  Someone on the RT team would then mark the bug as private, enabling discussion only between Eclipse Committers (all of them), the bug reporter, and anyone else you decide to include in the CC list.

Bug 223539 is a prime example of how this works.