]> xenbits.xensource.com Git - people/larsk/security-process.git/commitdiff
Use a public mailing list for predisclosure membership applications.
authorIan Jackson <ijackson@chiark.greenend.org.uk>
Fri, 16 Jan 2015 19:50:56 +0000 (19:50 +0000)
committerIan Jackson <Ian.Jackson@eu.citrix.com>
Mon, 19 Jan 2015 17:52:04 +0000 (17:52 +0000)
IMPLEMENTATION TASKS:
 * Create the mailing list (and check that it works from outside)

Signed-off-by: Ian Jackson <ijackson@chiark.greenend.org.uk>
Signed-off-by: Ian Jackson <Ian.Jackson@eu.citrix.com>
---
v2: Provide whole email address for predisclosure-applications@,
    but obfuscate it with <dot> and a <span>.
    Reword sentence about public mailing list as suggested by
    Ian Campbell.

security_vulnerability_process.html

index de5e83e6e5bf7b170262db559af4635e33d837f2..8870f8d93d5c3e880220afb0e6684b114db96488 100644 (file)
@@ -228,8 +228,10 @@ permitted to also make available the allocated CVE number. This is no
 longer permitted in accordance with MITRE policy.</p>
 <h3>Predisclosure list membership application process</h3>
 <p>Organisations who meet the criteria should contact
-security@xenproject if they wish to receive pre-disclosure of
-advisories. Please include in the e-mail:</p>
+predisclosure-applications@xenproject&lt;d<span>ot</span>&gt;org
+(which is a public mailing list) if they wish to receive
+pre-disclosure of advisories.
+<p>Please include in the e-mail:</p>
 <ul>
   <li>The name of your organization</li>
   <li>A brief description of why you fit the criteria, along with