From 27cacfedd0171ec0d1c163eeb24000466204e62a Mon Sep 17 00:00:00 2001 From: Ian Jackson Date: Fri, 16 Jan 2015 19:50:56 +0000 Subject: [PATCH] Use a public mailing list for predisclosure membership applications. IMPLEMENTATION TASKS: * Create the mailing list (and check that it works from outside) Signed-off-by: Ian Jackson Signed-off-by: Ian Jackson --- v2: Provide whole email address for predisclosure-applications@, but obfuscate it with and a . Reword sentence about public mailing list as suggested by Ian Campbell. --- security_vulnerability_process.html | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/security_vulnerability_process.html b/security_vulnerability_process.html index de5e83e..8870f8d 100644 --- a/security_vulnerability_process.html +++ b/security_vulnerability_process.html @@ -228,8 +228,10 @@ permitted to also make available the allocated CVE number. This is no longer permitted in accordance with MITRE policy.

Predisclosure list membership application process

Organisations who meet the criteria should contact -security@xenproject if they wish to receive pre-disclosure of -advisories. Please include in the e-mail:

+predisclosure-applications@xenproject<dot>org +(which is a public mailing list) if they wish to receive +pre-disclosure of advisories. +

Please include in the e-mail:

  • The name of your organization
  • A brief description of why you fit the criteria, along with -- 2.39.5