Re: [MAINTAINERS SUMMIT] Scaling our security process

Jiri Kosina <[email protected]> Mon, 27 Jul 2026 16:24:39 +0200 (CEST)
Newsgroups dev.linux.lists.ksummit
Message-ID <[email protected]>
On Tue, 14 Jul 2026, Sasha Levin wrote:

> 3. Do we want some sort of a shared distro security backport list? Every 
>    major distro pays people to backport security fixes, and they all do 
>    the same work in parallel behind separate walls. A list where 
>    upstream and distro security teams write and review backports 
>    together, would pool that effort and land fixes where users are. 
>    Sure, it allows for more leaks, but we end up causing these leaks 
>    ourselves when we release a fix without working backports.

Well, linux-distros@ is still there, and is used to coordinate security 
fixes in exactly this way consistently for vast majority of all the 
relevant projects, pretty much except for the kernel. With my distro hat 
on, I'd add "unfortunately".

At least our documentation now refers to it properly (in response to 
linux-distros@ becoming less rigid about their original rules) since 
0217f3944aebad1d, but it's still not, I believe, seen as a full-fledged 
part of the process.

Thanks,

-- 
Jiri Kosina
SUSE Labs