Re: GnuTLS | cli, serv: make it explicit that they are a testing program (!2086)
Read-only notification of GnuTLS library development activities <[email protected]> Sat, 28 Mar 2026 08:15:34 +0000
| Newsgroups | gmane.comp.encryption.gpg.gnutls.devel |
|---|---|
| Message-ID | <[email protected]> |
Daiki Ueno commented on a discussion on SECURITY.md: https://gitlab.com/gnutls/gnutls/-/merge_requests/2086#note_3199777416 > # Which issues are security issues > > A metric we consult to assessing security vulnerabilities is > -the [CVSS](https://www.first.org/cvss) metric. Only vulnerabilities > +the [CVSS](https://www.first.org/cvss) v3.1 metric. Only vulnerabilities > at the high or critical level are handled with this process. Other > issues are handled with the normal release process. > > +Some of the bundled programs, including gnutls-cli and gnutls-serv, > +are for testing and diagnostic purposes. Issues reported against those > +programs are not treated as a vulnerability. Applied, thanks. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2086#note_3199777416 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/sent_notifications/4-257u4zsm4rfcdh9t1ortxjnbv-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help _______________________________________________ Gnutls-devel mailing list [email protected] http://lists.gnupg.org/mailman/listinfo/gnutls-devel