On Thu, Oct 2, 2014 at 7:23 PM, R. Tyler Croy <[email protected]> wrote:
> Do you have any ideas on how we can improve the feedback times? Is it just a
> matter of getting more people involved in the SECURITY project?

By all means, if they are motivated to do serious investigations when
issues come in.

> Is there another list I'm not aware where security issues are discussed?

jenkinsci-cert, limited to those people who can also see the SECURITY component.

> On a related note, how are plugin developers who maintain plugins which have
> vulnerabilities disclosed against them looped into these conversations?

Not very well. Currently we cannot even add them on CC to the JIRA
issue, which makes it difficult to handle these.

-- 
You received this message because you are subscribed to the Google Groups 
"Jenkins Developers" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to