Re: [openstack-dev] [neutron] How to handle security issues in external repos?

2015-07-07 Thread Thierry Carrez
Jeremy Stanley wrote: > On 2015-07-06 20:25:25 +0200 (+0200), Henry Gessau wrote: >> Jeremy, a huge thanks for this fantastic reply! I have taken the liberty of >> copying your responses directly into Neutron's "contributing" guide: >> https://review.openstack.org/187267 >> >> I hope you don't mind

Re: [openstack-dev] [neutron] How to handle security issues in external repos?

2015-07-06 Thread Jeremy Stanley
On 2015-07-06 20:25:25 +0200 (+0200), Henry Gessau wrote: > Jeremy, a huge thanks for this fantastic reply! I have taken the liberty of > copying your responses directly into Neutron's "contributing" guide: > https://review.openstack.org/187267 > > I hope you don't mind. Quite the opposite--I'm h

Re: [openstack-dev] [neutron] How to handle security issues in external repos?

2015-07-06 Thread Henry Gessau
Jeremy, a huge thanks for this fantastic reply! I have taken the liberty of copying your responses directly into Neutron's "contributing" guide: https://review.openstack.org/187267 I hope you don't mind. On Fri, Jul 03, 2015, Jeremy Stanley wrote: > On 2015-07-03 22:01:38 +0200 (+0200), Henry Ge

Re: [openstack-dev] [neutron] How to handle security issues in external repos?

2015-07-03 Thread Jeremy Stanley
On 2015-07-03 22:01:38 +0200 (+0200), Henry Gessau wrote: [...] > The question now arises about what to do when a security issue is > found in such an external repository that integrates with Neutron. > > - How should such security issues be managed? The OpenStack Vulnerability Management Team (

[openstack-dev] [neutron] How to handle security issues in external repos?

2015-07-03 Thread Henry Gessau
In the Liberty cycle Neutron is mandating the splitting out of "third-party" plugins and drivers into separate repositories, see [1]. These external repositories will be managed by the maintainers of the code, who are independent from the neutron core maintainers. The question now arises about wha