Re: CRA compliance

Greg KH <[email protected]> Thu, 9 Oct 2025 16:12:34 +0200
Newsgroups dev.linux.lists.kernelci
Message-ID <2025100938-coronary-bronco-8a2b@gregkh>
On Thu, Oct 09, 2025 at 10:58:18PM +0900, Arisu Tachibana wrote:
> On Thu, Oct 9, 2025 at 10:06 PM Greg KH <[email protected]> wrote:
> > > Then for security breaches in KernelCI, it would be a best practice to create kernelci-security@
> > > mailing list for people to report issues and for us to community privately with parties running
> > > KernelCI infra too.
> >
> > "communicate privately" == "private communication channels" which opens
> > up a TON of legal issues, as I am want to talk at length with :)
> >
> > Be VERY VERY VERY careful with this, there's a whole boatload of
> > problems that you can get into when doing this as you are taking a
> > public project's communications private to specific companies/entities.
> >
> > Anyway, having a security@ address is great to REPORT bugs to, but
> > please refrain from using that to attempt to coordinate security fix
> > rollouts.  That way lies a death by a thousand paper cuts and
> > potentially talking to government entities when you least expect it.
> >
> > I can go into much more detail if people really want.
> >
> 
> Would be nice to have more detail on this topic in the future.

See my 2023 Kernel Recipies talk:
	https://www.youtube.com/watch?v=2TZe5EROFhE
around the 22:30 minute mark for more details.

thanks,

greg k-h