Vulnerability Management policy #167
No reviewers
Labels
No labels
meeting
backlog status
needs review
backlog status
ready
chore
documentation
planned
points
01
points
02
points
03
points
05
points
08
points
13
priority
high
priority
low
priority
medium
sprint status
blocked
sprint status
done
sprint status
in progress
sprint status
review
sprint status
to do
technical debt
work item
bug
work item
epic
work item
spike
work item
task
work item
user story
No milestone
No project
No assignees
5 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
epel/docs!167
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "security"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Vulnerability Management policy, as part of the discussions around https://pagure.io/epel/issue/159
Signed-off-by: Michel Alexandre Salim salimma@fedoraproject.org
What does this mean "should not be in EPEL"?
If a package shouldn't be in EPEL, that has nothing to do with CVE checking.
true, but this actually happened - libvncserver had lots of CVEs, and we only found out and retire it as part of looking at CVEs
I would change (I am not a native English speaker, hence might be wrong):
s/Confligting/Conflicting/
These bullet points seem to be using a mix of sentence fragments and complete sentences. We should stick with doing it one way or the other, with the appropriate capitalization and punctuation.
After the big restructuring, this PR got into a state that can't be fixed by just rebasing. The change is small, since it only involves the nav file, but if you want to continue working on this, I rebased it on this branch.
https://pagure.io/fork/dherrera/epel/tree/pr-307-rebase
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.Merge
Merge the changes and update on Forgejo.Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.