|
View:
New views
4 Messages
—
Rating Filter:
Alert me
|
|
|
Access to private bugsHi,
I'm one of the MySQL maintainers in Debian. Yesterday I prepared an update of the MySQL packages to fix CVE-2007-5969. Unfortunately the bugreport (#32111) is private, so I had to search the archive of the commiters mailinglist to get the patch. I don't know if there was a discussion about the bug or the patch. Is it possible to give maintainers of MySQL packages access to those bugs? It would make our life a bit easier. Norbert -- MySQL Packagers Mailing List For list archives: http://lists.mysql.com/packagers To unsubscribe: http://lists.mysql.com/packagers?unsub=lists@... |
|
|
Re: Access to private bugsMonday 10 December 2007 11:20:57 tarihinde Norbert Tretkowski şunları
yazmıştı: > Hi, > > I'm one of the MySQL maintainers in Debian. Yesterday I prepared an > update of the MySQL packages to fix CVE-2007-5969. Unfortunately the > bugreport (#32111) is private, so I had to search the archive of the > commiters mailinglist to get the patch. I don't know if there was a > discussion about the bug or the patch. > > Is it possible to give maintainers of MySQL packages access to those > bugs? It would make our life a bit easier. Indeed I am facing the same problem here as a packager for Pardus Linux. Regards, ismail -- Never learn by your mistakes, if you do you may never dare to try again. -- MySQL Packagers Mailing List For list archives: http://lists.mysql.com/packagers To unsubscribe: http://lists.mysql.com/packagers?unsub=lists@... |
|
|
Re: Access to private bugsHi!
Unfortunately, not at the moment :( We cannot allow you to see all private fields, attaches, and bugs (they could contain sensitive information that we're contractually required to keep confidential). We would need to introduce new flag "security bug" (or something) and new category of users that can see security-private bugs, but not other private bugs. But we'll open all private security bugs when a fixed 5.1 release is out. On Dec 10, Norbert Tretkowski wrote: > > I'm one of the MySQL maintainers in Debian. Yesterday I prepared an > update of the MySQL packages to fix CVE-2007-5969. Unfortunately the > bugreport (#32111) is private, so I had to search the archive of the > commiters mailinglist to get the patch. I don't know if there was a > discussion about the bug or the patch. > > Is it possible to give maintainers of MySQL packages access to those > bugs? It would make our life a bit easier. > Sergei -- __ ___ ___ ____ __ / |/ /_ __/ __/ __ \/ / Sergei Golubchik <serg@...> / /|_/ / // /\ \/ /_/ / /__ Principal Software Developer /_/ /_/\_, /___/\___\_\___/ MySQL GmbH, Dachauer Str. 37, D-80335 München <___/ Geschäftsführer: Kaj Arnö - HRB München 162140 -- MySQL Packagers Mailing List For list archives: http://lists.mysql.com/packagers To unsubscribe: http://lists.mysql.com/packagers?unsub=lists@... |
|
|
Re: Access to private bugsMonday 10 December 2007 13:16:20 tarihinde Sergei Golubchik şunları yazmıştı:
> Hi! > > Unfortunately, not at the moment :( > > We cannot allow you to see all private fields, attaches, and bugs (they > could contain sensitive information that we're contractually required to > keep confidential). We would need to introduce new flag "security bug" > (or something) and new category of users that can see security-private > bugs, but not other private bugs. Introducing a new flag in bugzilla shouldn't be hard I guess. That would allow us to write better advisories too. Regards, ismail -- Never learn by your mistakes, if you do you may never dare to try again. -- MySQL Packagers Mailing List For list archives: http://lists.mysql.com/packagers To unsubscribe: http://lists.mysql.com/packagers?unsub=lists@... |
| Free Forum Powered by Nabble | Forum Help |