public inbox for [email protected]
help / color / mirror / Atom feedFrom: Stefan Kaltenbrunner <[email protected]>
To: Tom Lane <[email protected]>
Cc: Josh Berkus <[email protected]>
Cc: [email protected]
Subject: Re: How to coordinate web team for security releases?
Date: Mon, 05 Feb 2007 21:40:09 +0100
Message-ID: <[email protected]> (raw)
In-Reply-To: <[email protected]>
References: <[email protected]>
<[email protected]>
<[email protected]>
Tom Lane wrote:
> Stefan Kaltenbrunner <[email protected]> writes:
>> So to keep it really under the hood would probably be quite difficult to do.
>
> Certainly. We're not looking for something absolutely bulletproof, we
> just don't want to read about it on pgsql-announce before the actual
> release ;-). Postgres isn't the sort of target that is likely to have
> blackhats tracking our anoncvs watching for interesting commits. We
> think it's probably enough if we can keep the topic out of the public
> mailing lists until the release announcement. Or at least, let's try
> to accomplish that before worrying about anything tighter.
That is probably a reasonable approach to the whole issue - and for the
anoncvs/buildfarm testing thing(if we want/need that even for such
patches) we could maybe look into the recent discussion on allowing
certain patches to be pulled from trusted people.
Maybe one could use that infrastructure to get basic buildfarm testing
without the need to commit to to the main public tree immediatly.
However the time gained from that might not be worth the pain ...
Stefan
view thread (50+ messages) latest in thread
reply
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Reply to all the recipients using the --to and --cc options:
reply via email
To: [email protected]
Cc: [email protected], [email protected], [email protected]
Subject: Re: How to coordinate web team for security releases?
In-Reply-To: <[email protected]>
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox