[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Bad press related to (missing) Debian security



also sprach Moritz Muehlenhoff <jmm@inutil.org> [2005.06.28.0156 +0200]:
> Have a look at the system we use for the testing security team (I
> always thought it originated in the security team):
> http://lists.alioth.debian.org/pipermail/secure-testing-commits/2005-June/thread.html
> 
> This system is so efficient that most communication is basically
> made through svn log messages.

Not meaning to disspell it, but isn't this essentially a bug
tracking system or ticket system done slightly differently?

What I think Debian (as a whole) needs is an improved issue tracker
with the following features:

  - single-bug subscription, through association with the bug (like
    bugzilla)
  - ability to set a bug as private, meaning that only associated
    people can view it or even find out about its existence.

add to that some automated way to open tickets for new CVEs and you
have a team todo list.

I know that this is not really what you guys want to hear and it's
probably best to adopt testing-security's approach for
stable-security. However, I am considering devoting more of my time
to this stuff in the future, and such a system would be needed for
some of the innovative approaches I have in mind. Thus, I'd love to
hear opinions.

-- 
Please do not send copies of list mail to me; I read the list!
 
 .''`.     martin f. krafft <madduck@debian.org>
: :'  :    proud Debian developer and author: http://debiansystem.info
`. `'`
  `-  Debian - when you have better things to do than fixing a system
 
Invalid/expired PGP subkeys? Use subkeys.pgp.net as keyserver!
 
DISCLAIMER: this entire message is privileged communication, intended
for the sole use of its recipients only. If you read it even though
you know you aren't supposed to, you're a poopy-head.

Attachment: signature.asc
Description: Digital signature


Reply to: