Friendica
daniel:// stenberg://
daniel:// stenberg://

daniel:// stenberg://

bagder@mastodon.social

daniel:// stenberg://

bagder@mastodon.social
I write curl. I don't know anything.
ActivityPub
2023-03-30 09:25:34 2023-03-29 12:19:39 2023-03-29 12:19:37 2954913

daniel:// stenberg://
daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

2 years ago • •

daniel:// stenberg://

2 years ago • •


pre-notification dilemmas:
daniel.haxx.se/blog/2023/03/29… - I will not tell the distros mailing list about pending #curl security vulnerabilities anymore. As requested.

Pre-notification dilemmas | daniel.haxx.se

daniel.haxx.se
#curl
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

networkException
mastodon - Link to source

networkException

in reply to daniel:// stenberg:// • 2 years ago • •
oh thats not great, I hope the people in charge of that mailing list reevaluate that decision
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

Moanos
mastodon - Link to source

Moanos

in reply to daniel:// stenberg:// • 2 years ago • •
What does an embargo mean? Is there any reason for the distros to not grant that?
  •  Languages
  •  Search Text
  •  Share via ...
in reply to Moanos

daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

in reply to Moanos • 2 years ago • •
@moanos it just means they don't tell anyone about the issue until the planned announcement date. And no, there is no (good) reason why they cannot just grant us this - if you ask me anyway.
@Moanos
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

Mike Connor
mastodon - Link to source

Mike Connor

in reply to daniel:// stenberg:// • 2 years ago • •
do we post Firefox updates to that list? We have had a very similar process around landing fixes for at least a decade…
  •  Languages
  •  Search Text
  •  Share via ...
in reply to Mike Connor

daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

in reply to Mike Connor • 2 years ago • •
@mconnor I don't know. Since I'm not a member of the list I cannot see any others' postings to it.
@Mike Connor
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

Frederik Braun �
mastodon - Link to source

Frederik Braun �

in reply to daniel:// stenberg:// • 2 years ago • •
@mconnor We have our own list and distros are subscribed to it. mozilla.org/en-US/about/govern… cc @dveditz

Mozilla Security Group Membership Policy

Mozilla
@Dan Veditz @Mike Connor
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

faker
mastodon - Link to source

faker

in reply to daniel:// stenberg:// • 2 years ago • •

I think that "they" in that sentence shouldn't be there

> this is an exception and they their policy says this is not acceptable for embargos.

  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

Johannes
mastodon - Link to source

Johannes

in reply to daniel:// stenberg:// • 2 years ago • •
That's too bad. You have been a very regular poster there with high quality reports. I've been on the list for a while, and while I appreciate all the work solar designer does for the community there (and why he doesn't want to extend embargoes) it's clear that the way it is run doesn't work for a lot of projects. Maybe it's time for an alternative.
  •  Languages
  •  Search Text
  •  Share via ...
in reply to Johannes

daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

in reply to Johannes • 2 years ago • •
@swars clearly something is wrong when neither curl, Firefox or the Linux kernel (can) post about their vulnerabilities there... But I'm not the one to tell what the alternative should be.
@Johannes
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

Johannes
mastodon - Link to source

Johannes

in reply to daniel:// stenberg:// • 2 years ago • •
I agree. An alternative could be a list like distros, but with no (or very lax) ground rules, where the reporters specify the rules for the embargoes. Don't know if this would work out, as this also has quite some potential for problems, but it might be worth a try.
  •  Languages
  •  Search Text
  •  Share via ...
⇧