On Sat, 05 Jan 2008 20:52:49 -0600 Martin Jackson <[EMAIL PROTECTED]> wrote: > That's making the assumption that anyone looked at it, of course. > Please note comment #9 on > http://bugs.gentoo.org/show_bug.cgi?id=198346. It was still ~8 days > from then that the setuptools keyword was added. > > So, we have examples of impact due to delay in keywords/etc. Shall > we proceed with the discussion of what to do about it?
http://www.gentoo.org/security/en/vulnerability-policy.xml The target for that GLSA was 20 days. 8 days is well within target. What are you moaning about? -- Ciaran McCreesh
signature.asc
Description: PGP signature
