[ovs-dev] [PATCH] SECURITY.md: Increase embargo period from 3-5 to 10-15 business days.

Ryan Moats rmoats at us.ibm.com
Sat Apr 2 22:07:50 UTC 2016


"dev" <dev-bounces at openvswitch.org> wrote on 03/31/2016 11:54:03 PM:

> From: Ben Pfaff <blp at ovn.org>
> To: dev at openvswitch.org
> Cc: Ben Pfaff <blp at ovn.org>
> Date: 03/31/2016 11:54 PM
> Subject: [ovs-dev] [PATCH] SECURITY.md: Increase embargo period from
> 3-5 to 10-15 business days.
> Sent by: "dev" <dev-bounces at openvswitch.org>
>
> When we recently ran a genuine vulnerability through this process, we
> discovered that 3-5 days was far too short.  The business processes
behind
> releasing fixed versions of software at companies that use Open vSwitch
> cannot cope with such rapid turnaround, due e.g. to QA and other
processes.
>
> Signed-off-by: Ben Pfaff <blp at ovn.org>
> ---

After some thought ...

Acked-by: Ryan Moats <rmoats at us.ibm.com>



More information about the dev mailing list