-----Original Message----- On October 6, 2017 6:51 PM, Jonathan Nieder wrote >Randall S. Becker wrote: >> I wonder whether there is some mechanism for providing official >> responses from platform ports relating to security CVE reports, like CVE-2017-14867. >This question is too abstract for me. Can you say more concretely what you are trying to do? >E.g. are you asking how you would communicate to users of your port that CVE-2017-14867 ?does not apply to them? Or are you asking where to start a conversation about >who a bug applies to? Or something else? The first one, mostly. When looking at CVE-2017-14867, there are places like https://nvd.nist.gov/vuln/detail/CVE-2017-14867 where the issue is discussed. It provides hyperlinks to various platform discussions. Unfortunately for me, I am not an HPE employee - and even if I was, there is no specific site where I can publicly discuss the vulnerability. I'm looking to the group here for advice on how to get the word out that it does not appear to apply to the HPE NonStop Git port. The question of where to best do that for any CVE pertaining to git as applicable to the NonStop Port is question #1. Question #2 - probably more relevant to the specific issue and this group - is whether the vulnerability is contained to Git's use of Perl SCM and since NonStop's Perl does not support SCM, the vulnerability may not be relevant, but I'm not really enough of a Perl guru to make that determination. Cheers, Randall -- Brief whoami: NonStop&UNIX developer since approximately UNIX(421664400)/NonStop(211288444200000000) -- In my real life, I talk too much.