Re: CRA compliance
Greg KH <[email protected]> Thu, 9 Oct 2025 16:12:34 +0200
| Newsgroups | dev.linux.lists.kernelci |
|---|---|
| Message-ID | <2025100938-coronary-bronco-8a2b@gregkh> |
On Thu, Oct 09, 2025 at 10:58:18PM +0900, Arisu Tachibana wrote: > On Thu, Oct 9, 2025 at 10:06 PM Greg KH <[email protected]> wrote: > > > Then for security breaches in KernelCI, it would be a best practice to create kernelci-security@ > > > mailing list for people to report issues and for us to community privately with parties running > > > KernelCI infra too. > > > > "communicate privately" == "private communication channels" which opens > > up a TON of legal issues, as I am want to talk at length with :) > > > > Be VERY VERY VERY careful with this, there's a whole boatload of > > problems that you can get into when doing this as you are taking a > > public project's communications private to specific companies/entities. > > > > Anyway, having a security@ address is great to REPORT bugs to, but > > please refrain from using that to attempt to coordinate security fix > > rollouts. That way lies a death by a thousand paper cuts and > > potentially talking to government entities when you least expect it. > > > > I can go into much more detail if people really want. > > > > Would be nice to have more detail on this topic in the future. See my 2023 Kernel Recipies talk: https://www.youtube.com/watch?v=2TZe5EROFhE around the 22:30 minute mark for more details. thanks, greg k-h