Re: [MAINTAINERS SUMMIT] Scaling our security process
Jiri Kosina <[email protected]> Mon, 27 Jul 2026 16:24:39 +0200 (CEST)
| Newsgroups | dev.linux.lists.ksummit |
|---|---|
| Message-ID | <[email protected]> |
On Tue, 14 Jul 2026, Sasha Levin wrote: > 3. Do we want some sort of a shared distro security backport list? Every > major distro pays people to backport security fixes, and they all do > the same work in parallel behind separate walls. A list where > upstream and distro security teams write and review backports > together, would pool that effort and land fixes where users are. > Sure, it allows for more leaks, but we end up causing these leaks > ourselves when we release a fix without working backports. Well, linux-distros@ is still there, and is used to coordinate security fixes in exactly this way consistently for vast majority of all the relevant projects, pretty much except for the kernel. With my distro hat on, I'd add "unfortunately". At least our documentation now refers to it properly (in response to linux-distros@ becoming less rigid about their original rules) since 0217f3944aebad1d, but it's still not, I believe, seen as a full-fledged part of the process. Thanks, -- Jiri Kosina SUSE Labs