Re: [VOTE] commit Low/Moderate severity security issues to public repos
Frank Gingras <[email protected]> Tue, 12 May 2026 16:31:05 -0400
| Newsgroups | gmane.comp.apache.devel |
|---|---|
| Message-ID | <CAOY50mv=mKi92m0Amkg+0-iRG7wQfMaf32b8MDPTXgEn-WXR9w@mail.gmail.com> |
--000000000000c03d560651a4be0c Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable On Tue, May 12, 2026 at 4:24=E2=80=AFPM Christophe JAILLET < [email protected]> wrote: > > Le 08/05/2026 =C3=A0 13:31, Joe Orton a =C3=A9crit : > > Hi all, another vote - > > > > We currently track all security issues in private, pushing these to the > > public repos only during the preparation for a release. This adds > > significant overhead for committers handling the current surge of > > reports - a surge which mostly comprises Low severity issues. It also > > delays us getting CI runs, which potentially delays the release, exactl= y > > as happened with the recent mod_auth_digest fix in 2.4.67. > > > > I'm proposing that we change the process: once we confirm a Low (and > > maybe Moderate) severity issue, the fix can be pushed to the public > > repos like any other change, with a deliberately obfuscated commit > > message to conceal the security impact. The ASF Security team is fine > > with this approach per [1], though cautions us to not keep the obscured > > commits public for too long before a release. > > > > Please vote: > > > > [ ] No - keep the current process > > [X] Yes - push Low severity issues as obfuscated public commits > > [ ] Yes - push Low+Moderate severity issues as obfuscated public commit= s > > > > If you're fine with either Low or Low+Moderate vote "Yes" on both and > > we'll see where the majority lies? > > > > Regards, Joe > > > > [1] > https://cwiki.apache.org/confluence/display/SECURITY/Working+In+Private > > > I was initially wary of the third option, but I reconsidered the risks. [x ] Yes - push Low severity issues as obfuscated public commits [x ] Yes - push Low+Moderate severity issues as obfuscated public commits --000000000000c03d560651a4be0c Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div dir=3D"ltr"><br></div><br><div class=3D"gmail_quote g= mail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">On Tue, May 12,= 2026 at 4:24=E2=80=AFPM Christophe JAILLET <<a href=3D"mailto:christoph= [email protected]">[email protected]</a>> wrote:<br></div= ><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border= -left:1px solid rgb(204,204,204);padding-left:1ex"><br> Le 08/05/2026 =C3=A0 13:31, Joe Orton a =C3=A9crit=C2=A0:<br> > Hi all, another vote -<br> ><br> > We currently track all security issues in private, pushing these to th= e<br> > public repos only during the preparation for a release. This adds<br> > significant overhead for committers handling the current surge of<br> > reports - a surge which mostly comprises Low severity issues. It also<= br> > delays us getting CI runs, which potentially delays the release, exact= ly<br> > as happened with the recent mod_auth_digest fix in 2.4.67.<br> ><br> > I'm proposing that we change the process: once we confirm a Low (a= nd<br> > maybe Moderate) severity issue, the fix can be pushed to the public<br= > > repos like any other change, with a deliberately obfuscated commit<br> > message to conceal the security impact. The ASF Security team is fine<= br> > with this approach per [1], though cautions us to not keep the obscure= d<br> > commits public for too long before a release.<br> ><br> > Please vote:<br> ><br> > [ ] No - keep the current process<br> > [X] Yes - push Low severity issues as obfuscated public commits<br> > [ ] Yes - push Low+Moderate severity issues as obfuscated public commi= ts<br> ><br> > If you're fine with either Low or Low+Moderate vote "Yes"= ; on both and<br> > we'll see where the majority lies?<br> ><br> > Regards, Joe<br> ><br> > [1] <a href=3D"https://cwiki.apache.org/confluence/display/SECURITY/Wo= rking+In+Private" rel=3D"noreferrer" target=3D"_blank">https://cwiki.apache= .org/confluence/display/SECURITY/Working+In+Private</a><br> ><br></blockquote><div><br></div><div>I was initially wary of the third = option, but I reconsidered the risks.</div><div><br></div>[x ] Yes - push L= ow severity issues as obfuscated public commits<br>[x ] Yes - push Low+Mode= rate severity issues as obfuscated public commits<br><div>=C2=A0</div></div= ></div> --000000000000c03d560651a4be0c--