Re: [VOTE] commit Low/Moderate severity security issues to public repos

Frank Gingras <[email protected]> Tue, 12 May 2026 16:31:05 -0400
Newsgroups gmane.comp.apache.devel
Message-ID <CAOY50mv=mKi92m0Amkg+0-iRG7wQfMaf32b8MDPTXgEn-WXR9w@mail.gmail.com>
--000000000000c03d560651a4be0c
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

On Tue, May 12, 2026 at 4:24=E2=80=AFPM Christophe JAILLET <
[email protected]> wrote:

>
> Le 08/05/2026 =C3=A0 13:31, Joe Orton a =C3=A9crit :
> > Hi all, another vote -
> >
> > We currently track all security issues in private, pushing these to the
> > public repos only during the preparation for a release. This adds
> > significant overhead for committers handling the current surge of
> > reports - a surge which mostly comprises Low severity issues. It also
> > delays us getting CI runs, which potentially delays the release, exactl=
y
> > as happened with the recent mod_auth_digest fix in 2.4.67.
> >
> > I'm proposing that we change the process: once we confirm a Low (and
> > maybe Moderate) severity issue, the fix can be pushed to the public
> > repos like any other change, with a deliberately obfuscated commit
> > message to conceal the security impact. The ASF Security team is fine
> > with this approach per [1], though cautions us to not keep the obscured
> > commits public for too long before a release.
> >
> > Please vote:
> >
> > [ ] No - keep the current process
> > [X] Yes - push Low severity issues as obfuscated public commits
> > [ ] Yes - push Low+Moderate severity issues as obfuscated public commit=
s
> >
> > If you're fine with either Low or Low+Moderate vote "Yes" on both and
> > we'll see where the majority lies?
> >
> > Regards, Joe
> >
> > [1]
> https://cwiki.apache.org/confluence/display/SECURITY/Working+In+Private
> >
>

I was initially wary of the third option, but I reconsidered the risks.

[x ] Yes - push Low severity issues as obfuscated public commits
[x ] Yes - push Low+Moderate severity issues as obfuscated public commits

--000000000000c03d560651a4be0c
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div dir=3D"ltr"><br></div><br><div class=3D"gmail_quote g=
mail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">On Tue, May 12,=
 2026 at 4:24=E2=80=AFPM Christophe JAILLET &lt;<a href=3D"mailto:christoph=
[email protected]">[email protected]</a>&gt; wrote:<br></div=
><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border=
-left:1px solid rgb(204,204,204);padding-left:1ex"><br>
Le 08/05/2026 =C3=A0 13:31, Joe Orton a =C3=A9crit=C2=A0:<br>
&gt; Hi all, another vote -<br>
&gt;<br>
&gt; We currently track all security issues in private, pushing these to th=
e<br>
&gt; public repos only during the preparation for a release. This adds<br>
&gt; significant overhead for committers handling the current surge of<br>
&gt; reports - a surge which mostly comprises Low severity issues. It also<=
br>
&gt; delays us getting CI runs, which potentially delays the release, exact=
ly<br>
&gt; as happened with the recent mod_auth_digest fix in 2.4.67.<br>
&gt;<br>
&gt; I&#39;m proposing that we change the process: once we confirm a Low (a=
nd<br>
&gt; maybe Moderate) severity issue, the fix can be pushed to the public<br=
>
&gt; repos like any other change, with a deliberately obfuscated commit<br>
&gt; message to conceal the security impact. The ASF Security team is fine<=
br>
&gt; with this approach per [1], though cautions us to not keep the obscure=
d<br>
&gt; commits public for too long before a release.<br>
&gt;<br>
&gt; Please vote:<br>
&gt;<br>
&gt; [ ] No - keep the current process<br>
&gt; [X] Yes - push Low severity issues as obfuscated public commits<br>
&gt; [ ] Yes - push Low+Moderate severity issues as obfuscated public commi=
ts<br>
&gt;<br>
&gt; If you&#39;re fine with either Low or Low+Moderate vote &quot;Yes&quot=
; on both and<br>
&gt; we&#39;ll see where the majority lies?<br>
&gt;<br>
&gt; Regards, Joe<br>
&gt;<br>
&gt; [1] <a href=3D"https://cwiki.apache.org/confluence/display/SECURITY/Wo=
rking+In+Private" rel=3D"noreferrer" target=3D"_blank">https://cwiki.apache=
.org/confluence/display/SECURITY/Working+In+Private</a><br>
&gt;<br></blockquote><div><br></div><div>I was initially wary of the third =
option, but I reconsidered the risks.</div><div><br></div>[x ] Yes - push L=
ow severity issues as obfuscated public commits<br>[x ] Yes - push Low+Mode=
rate severity issues as obfuscated public commits<br><div>=C2=A0</div></div=
></div>

--000000000000c03d560651a4be0c--