public inbox for gentoo-dev@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-dev] Proposed security policy for web-based apps
@ 2005-07-05 20:21 Stuart Herbert
  2005-07-05 20:35 ` Mike Frysinger
                   ` (4 more replies)
  0 siblings, 5 replies; 18+ messages in thread
From: Stuart Herbert @ 2005-07-05 20:21 UTC (permalink / raw
  To: gentoo-dev

[-- Attachment #1: Type: text/plain, Size: 1848 bytes --]

Hi,

I'd like to introduce the following security policy for web-based apps.
If there are no objections, every new web-based app will have to conform
to the policy before it can be added to the tree.  Every existing
web-based app will have to conform to the policy by the end of August,
or I will remove it from the tree.

The proposed policy is simply that:

1. The Gentoo package's maintainer will identify one *named* contact
   UPSTREAM for security-related matters, and one named general contact
   UPSTREAM (as a fallback for when the security contact is
   unreachable).
2. This information will be held on the Dev Wiki.
3. This information will be checked every three months to ensure it
   remains valid.
4. In situations where the UPSTREAM contacts are unreachable, and no
   new contact can be identified, the package will be masked and
   marked for removal from the Portage tree (ie it fails this policy)

I believe that security holes will be discovered from time to time.  I
want to make sure that, when a hole has been found, everything's in
place for us to work with UPSTREAM at the greatest possible speed to get
things resolved.

I would rather we only distributed web-based apps where we can be
confident that security is taken appropriately seriously UPSTREAM.  Web
servers are too easy a target for us to be distributing software we
can't be confident about.

Thoughts, comments, other (constructive) feedback?

Best regards,
Stu
-- 
Stuart Herbert                                         stuart@gentoo.org
Gentoo Developer                                  http://www.gentoo.org/
                                              http://stu.gnqs.org/diary/

GnuGP key id# F9AFC57C available from http://pgp.mit.edu
Key fingerprint = 31FB 50D4 1F88 E227 F319  C549 0C2F 80BA F9AF C57C
--

[-- Attachment #2: This is a digitally signed message part --]
[-- Type: application/pgp-signature, Size: 189 bytes --]

^ permalink raw reply	[flat|nested] 18+ messages in thread

end of thread, other threads:[~2005-07-10 22:44 UTC | newest]

Thread overview: 18+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2005-07-05 20:21 [gentoo-dev] Proposed security policy for web-based apps Stuart Herbert
2005-07-05 20:35 ` Mike Frysinger
2005-07-05 20:40   ` Lance Albertson
2005-07-10  8:57     ` Stuart Herbert
2005-07-10 22:39       ` Andrej Kacian
2005-07-05 21:52 ` Alec Warner
2005-07-05 22:12   ` David Morgan
2005-07-10  9:02     ` Stuart Herbert
2005-07-05 22:21   ` Renat Lumpau
2005-07-10  8:59   ` Stuart Herbert
2005-07-05 22:30 ` Marius Mauch
2005-07-10  9:06   ` Stuart Herbert
2005-07-06 18:10 ` Radoslaw Stachowiak
2005-07-08  9:58   ` Diego 'Flameeyes' Pettenò
2005-07-08 10:58     ` Martin Schlemmer
2005-07-10  9:16       ` Stuart Herbert
2005-07-10  9:08   ` Stuart Herbert
2005-07-08  9:42 ` Aaron Walker

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox