From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from lists.gentoo.org ([140.105.134.102] helo=robin.gentoo.org) by nuthatch.gentoo.org with esmtp (Exim 4.43) id 1DpvPq-0001f8-4M for garchives@archives.gentoo.org; Tue, 05 Jul 2005 21:57:18 +0000 Received: from robin.gentoo.org (localhost [127.0.0.1]) by robin.gentoo.org (8.13.4/8.13.4) with SMTP id j65LtLn6025617; Tue, 5 Jul 2005 21:55:21 GMT Received: from egr.msu.edu (jeeves.egr.msu.edu [35.9.37.127]) by robin.gentoo.org (8.13.4/8.13.4) with ESMTP id j65Lq1nX003089 for ; Tue, 5 Jul 2005 21:52:02 GMT Received: from [192.168.2.171] (207-72-142-241.dovers_res_net.spartan-net.net [207.72.142.241] (may be forged)) (authenticated bits=0) by egr.msu.edu (8.13.4/8.13.4) with ESMTP id j65Lqjnx004834 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO) for ; Tue, 5 Jul 2005 17:52:45 -0400 (EDT) Message-ID: <42CB012F.1040106@egr.msu.edu> Date: Tue, 05 Jul 2005 17:52:47 -0400 From: Alec Warner User-Agent: Mozilla Thunderbird 1.0.2 (X11/20050704) X-Accept-Language: en-us, en Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-dev@gentoo.org Reply-to: gentoo-dev@lists.gentoo.org MIME-Version: 1.0 To: gentoo-dev@lists.gentoo.org Subject: Re: [gentoo-dev] Proposed security policy for web-based apps References: <1120594895.6234.243.camel@mogheiden.gnqs.org> In-Reply-To: <1120594895.6234.243.camel@mogheiden.gnqs.org> X-Enigmail-Version: 0.90.2.0 X-Enigmail-Supports: pgp-inline, pgp-mime Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit X-Archives-Salt: 90854034-9a2e-4051-b151-721bd5080eb4 X-Archives-Hash: 5c08dee29e4eda23aa4cefa92c5cc39d -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Stuart Herbert wrote: > Hi, > > > 1. The Gentoo package's maintainer will identify one *named* contact > UPSTREAM for security-related matters, and one named general contact > UPSTREAM (as a fallback for when the security contact is > unreachable). > 2. This information will be held on the Dev Wiki. > 3. This information will be checked every three months to ensure it > remains valid. Are you volunteering to do 3? If not, who will? > 4. In situations where the UPSTREAM contacts are unreachable, and no > new contact can be identified, the package will be masked and > marked for removal from the Portage tree (ie it fails this policy) > > Thoughts, comments, other (constructive) feedback? > > Best regards, > Stu -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.1 (GNU/Linux) Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org iQIVAwUBQssBL2zglR5RwbyYAQKf8Q//QqbVG+xReAF5WyZMHOfOS0zoM0UJZRFJ M7WM28JVR6aNAD4hVcv8EKVMLvt6nPiIu2REsO9ZrZwzIdBm8uLxqdnX76ZysW/6 h10igkCBa78RfuNHbul4muPk1SyAWg3ZextltaMXPrO8bDfoTENcLzp8+NqDyqel 6Ncr/pEcZnEJABKmDfuT/ehtI89+wps51Fkdq7wa8z+EXGCDd1HGNTA3x1OImgDM VaHlLjGVS1lLcXGmZYKCZGvfKzbF/d9xJZ/LwdG+CpJD02avJ4iVv/51y/eGiVzm CwB9d+5wCq5YZFBLOXr8HXFJhYkzSXuGZfbKXisdhzui5MqpErpMQw1TNATY//ha HfFlYjnftS2vjzO/M9aiQqdqXF4HiejKRJGWVwxcqenFjj566t+uTvomwgI/2YLi /yimNyoyG3/ueLLSEMtyo6MURrjT9bbohUVH7pMr3RHNbNjtn3K9omEB4Ngh8L2q kA3hjoQRy1a6gNhG6eHg0j9sBmGb2TEBK/nMKCdyqONH+X/cdGCMIreMxcZ5pqu7 hBD/azcZI8jJr+tb0y3NHcfaT653HDAyeyOCD1OiDDlZeqzi1IGGW1p0ZHqg5J/+ NiGXnbCBT6NKzjvYfQ4nMYJaHGoZQDj8wHyFSUGKUFLjQ+L9X1ros8a1URhfinRf 0pDyFPfTmAI= =6nmQ -----END PGP SIGNATURE----- -- gentoo-dev@gentoo.org mailing list