From the secteam point of view, we haven't changed anything in the way we send 
messages to the mailing lists. I have double checked and all SAs are sent to 
the three addresses listed. I suspect this is likely fallout of the mailing 
list change over.

I can say for my part, I have gotten a copy of the messages from both the 
freebsd-announce and freebsd-security mailing lists for the SAs I have sent out 
(I'm not subscribed to the freebsd-security-notifications list). I just 
confirmed the headers for the 2 copies of SA-22:08.zlib that I received that it 
is routing through the lists. 

It does appear as though the messages are not properly archiving into the 
mailing list archives. Adding postmaster to the thread for them to dig into why 
that might be.

Gordon
Hat: security-officer

> On Apr 18, 2022, at 12:57 PM, Kevin Oberman <[email protected]> wrote:
> 
> As per the FreeBSD Security Information web page 
> <https://www.freebsd.org/security/>, security notifications are sent to:
> [email protected] 
> <mailto:[email protected]>
> [email protected] <mailto:[email protected]>
> [email protected] <mailto:[email protected]>
> This policy has lately been ignored. No postings show up in the archives of 
> [email protected] 
> <mailto:[email protected]> since January. Likewise 
> for freebsd-announce. The only list showing the April 6 announcements is this 
> one, [email protected] <mailto:[email protected]>.
> 
> In the past, Security Announcements and Errata Notes have also been copied to 
> the stable and current lists as appropriate, although this is not mentioned.  
> This delayed the update of my systems by several days. Fortunately, only one 
> of these vulnerabilities was relevant to my systems.
> 
> Even though the announcements are almost 2 weeks old, it is still likely that 
> some people are unaware of them, so I would strongly urge that they be posted 
> to, at least, FreeBSD-Announce and  FreeBSD-Stable lists.
> 
> In passing, I will note  that the same issue appears to be occurring with 
> posts of Errata Notices.
> -- 
> Kevin Oberman, Part time kid herder and retired Network Engineer
> E-mail: [email protected] <mailto:[email protected]>
> PGP Fingerprint: D03FB98AFA78E3B78C1694B318AB39EF1B055683

Reply via email to