Re: [OE-core] [yocto] Renaming the yocto-security mailing list
Michael Halstead <[email protected]>
| Newsgroups | org.yoctoproject.lists.yocto,org.openembedded.lists.openembedded-core |
|---|---|
| Message-ID | <CADfgfoY5YhZo15CU3+DA0MnrGP3aRYUOi0BLqgF51_UVYyNsjQ@mail.gmail.com> |
On Wed, Aug 20, 2025 at 5:35 AM Marta Rybczynska <[email protected]> wrote: > > This is an excellent question. We do want new discussions around security topics, so this moderation should be efficient. > > Kind regards, > Marta > > On Wed, Aug 20, 2025 at 11:53 AM Philip Balister <[email protected]> wrote: >> >> Michael, >> >> Who are the moderators? I am currently the only moderator. I'll email the security group and ask for more volunteers. >> >> Philip >> >> On 8/19/25 6:41 PM, Michael Halstead via lists.openembedded.org wrote: >> > I've updated [email protected] to require >> > moderator approval for new topics. This should prevent private >> > security reports from being posted publicly by mistake. >> > [email protected] is not a private list but instead forwards >> > email received to members of the security team. >> > >> > I believe this solves the issue without requiring changes to the list >> > name or documentation. >> > >> > On Tue, Aug 19, 2025 at 2:50 PM Rudolf J Streif via >> > lists.yoctoproject.org >> > <[email protected]> wrote: >> >> >> >> I don't any specifics about the incident. I suppose security-relevant >> >> information was submitted to a public mailing list. A private mailing >> >> list may help but in the end it's security-by-obfuscation. A mailing >> >> list for submitting CVEs is not the best choice imho. A secure web form >> >> should be better. We have a CVE Status page >> >> (https://wiki.yoctoproject.org/wiki/CVE_Status) that lists the current >> >> acknowledged CVEs but of course reported CVEs should go through an >> >> investigative filter and potentially sanitizing first before put on that >> >> page. >> >> >> >> :rjs >> >> >> >> On 8/19/25 8:08 AM, Marta Rybczynska via lists.yoctoproject.org wrote: >> >>> Hello all, >> >>> yesterday's incident confirms that yocto-security has a confusing name >> >>> that might cause confidential reports to arrive there. >> >>> >> >>> What about renaming the list to yocto-security-discussion or similar? >> >>> And eventually redirect yocto-security to the private security list. >> >>> >> >>> My reasoning: we shouldn't rename the private list as people might use >> >>> old versions of documentation and we want them to address the correct >> >>> private list when needed. It is less critical if a message expected >> >>> for the public list reaches the private one, than otherwise. >> >>> >> >>> What do you think? What is the process to do the change? >> >>> >> >>> Kind regards, >> >>> Marta >> >>> >> >>> >> >>> >> >> >> >> >> >> >> > >> > >> > >> > >> > -=-=-=-=-=-=-=-=-=-=-=- >> > Links: You receive all messages sent to this group. >> > View/Reply Online (#222151): https://lists.openembedded.org/g/openembedded-core/message/222151 >> > Mute This Topic: https://lists.openembedded.org/mt/114790185/384425 >> > Group Owner: [email protected] >> > Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] >> > -=-=-=-=-=-=-=-=-=-=-=- >> > >> -- Michael Halstead Linux Foundation / Yocto Project Systems Operations Engineer