Vulnerability Management policy #167

Open
salimma wants to merge 1 commit from security into main
Contributor

Vulnerability Management policy, as part of the discussions around https://pagure.io/epel/issue/159

Signed-off-by: Michel Alexandre Salim salimma@fedoraproject.org

Vulnerability Management policy, as part of the discussions around https://pagure.io/epel/issue/159 Signed-off-by: Michel Alexandre Salim <salimma@fedoraproject.org>
Owner

What does this mean "should not be in EPEL"?
If a package shouldn't be in EPEL, that has nothing to do with CVE checking.

What does this mean "should not be in EPEL"? If a package shouldn't be in EPEL, that has nothing to do with CVE checking.
Author
Contributor

What does this mean "should not be in EPEL"?
If a package shouldn't be in EPEL, that has nothing to do with CVE checking.

true, but this actually happened - libvncserver had lots of CVEs, and we only found out and retire it as part of looking at CVEs

> What does this mean "should not be in EPEL"? > If a package shouldn't be in EPEL, that has nothing to do with CVE checking. true, but this actually happened - libvncserver had lots of CVEs, and we only found out and retire it as part of looking at CVEs
Contributor

I would change (I am not a native English speaker, hence might be wrong):

  • "critical bug not" to "critical, but not" (or "critical and not")
  • "above but retire" to "above, but retire" (or "above and retire")
I would change (I am not a native English speaker, hence might be wrong): - "critical bug not" to "critical, but not" (or "critical and not") - "above but retire" to "above, but retire" (or "above and retire")
Owner

s/Confligting/Conflicting/

s/Confligting/Conflicting/
Owner

These bullet points seem to be using a mix of sentence fragments and complete sentences. We should stick with doing it one way or the other, with the appropriate capitalization and punctuation.

These bullet points seem to be using a mix of sentence fragments and complete sentences. We should stick with doing it one way or the other, with the appropriate capitalization and punctuation.
Owner

After the big restructuring, this PR got into a state that can't be fixed by just rebasing. The change is small, since it only involves the nav file, but if you want to continue working on this, I rebased it on this branch.

https://pagure.io/fork/dherrera/epel/tree/pr-307-rebase

After the big restructuring, this PR got into a state that can't be fixed by just rebasing. The change is small, since it only involves the nav file, but if you want to continue working on this, I rebased it on this branch. https://pagure.io/fork/dherrera/epel/tree/pr-307-rebase
This pull request is broken due to missing fork information.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin security:security
git switch security

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch main
git merge --no-ff security
git switch security
git rebase main
git switch main
git merge --ff-only security
git switch security
git rebase main
git switch main
git merge --no-ff security
git switch main
git merge --squash security
git switch main
git merge --ff-only security
git switch main
git merge security
git push origin main
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
5 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
epel/docs!167
No description provided.