Re: [yocto] Renaming the yocto-security mailing list

Rudolf J Streif <[email protected]>
Newsgroups org.yoctoproject.lists.yocto
Message-ID <[email protected]>
I don't any specifics about the incident. I suppose security-relevant 
information was submitted to a public mailing list. A private mailing 
list may help but in the end it's security-by-obfuscation. A mailing 
list for submitting CVEs is not the best choice imho. A secure web form 
should be better. We have a CVE Status page 
(https://wiki.yoctoproject.org/wiki/CVE_Status) that lists the current 
acknowledged CVEs but of course reported CVEs should go through an 
investigative filter and potentially sanitizing first before put on that 
page.

:rjs

On 8/19/25 8:08 AM, Marta Rybczynska via lists.yoctoproject.org wrote:
> Hello all,
> yesterday's incident confirms that yocto-security has a confusing name 
> that might cause confidential reports to arrive there.
>
> What about renaming the list to yocto-security-discussion or similar? 
> And eventually redirect yocto-security to the private security list.
>
> My reasoning: we shouldn't rename the private list as people might use 
> old versions of documentation and we want them to address the correct 
> private list when needed. It is less critical if a message expected 
> for the public list reaches the private one, than otherwise.
>
> What do you think? What is the process to do the change?
>
> Kind regards,
> Marta
>
> -=-=-=-=-=-=-=-=-=-=-=-
> Links: You receive all messages sent to this group.
> View/Reply Online (#65770): https://lists.yoctoproject.org/g/yocto/message/65770
> Mute This Topic: https://lists.yoctoproject.org/mt/114782606/3617932
> Group Owner: [email protected]
> Unsubscribe: https://lists.yoctoproject.org/g/yocto/unsub [[email protected]]
> -=-=-=-=-=-=-=-=-=-=-=-
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.