Hi Hauke,

I send this mail to the public mailing list because I want such a discussion. I do not think these are big problems we have to manage in private and then release in a coordinated way.
> [...]

I agree, such "low impact" report can be published right away and fixed on the next occasion, basically handle them like an ordinary issue report.

The disclosure / CVE request flow etc. should be reserved for high impact issues like unauthenticated code injection or similar.

Regards,
Jo

_______________________________________________
openwrt-devel mailing list
[email protected]
https://lists.openwrt.org/mailman/listinfo/openwrt-devel

Reply via email to