Re: Security testing: need for a security policy, and a security-critical package process

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Mon, 2009-11-23 at 14:33 -0800, Jesse Keating wrote:
> On Mon, 2009-11-23 at 14:08 -0800, Adam Williamson wrote:
> > This list of packages
> > would be what the QA team would test with regard to the security policy.
> > We also believe there ought to be a process for maintaining this list,
> > and additions to the packaging guidelines for any new package which
> > would be on this list or any existing package for which a proposed
> > change would add it to this list. We could also hook AutoQA into this
> > process, to run additional tests on security-sensitive packages or alert
> > us when a package change was submitted which added security-sensitive
> > elements to an existing package. 
> 
> I would warn against trying to have a manual static list of packages
> here, same as crit-path.  These packages need to be discoverable via
> software.

yeah, sorry - I was thinking along the same lines, having a script to
generate the list. I thought that was kind of implied in what I wrote
but I guess not :)

-- 
Adam Williamson
Fedora QA Community Monkey
IRC: adamw | Fedora Talk: adamwill AT fedoraproject DOT org
http://www.happyassassin.net

-- 
fedora-devel-list mailing list
fedora-devel-list@xxxxxxxxxx
https://www.redhat.com/mailman/listinfo/fedora-devel-list

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Index of Archives]     [Fedora Announce]     [Fedora Kernel]     [Fedora Testing]     [Fedora Formulas]     [Fedora PHP Devel]     [Kernel Development]     [Fedora Legacy]     [Fedora Maintainers]     [Fedora Desktop]     [PAM]     [Red Hat Development]     [Gimp]     [Yosemite News]
  Powered by Linux