On 29 April 2014 06:51, Michael S. Tsirkin <mst@xxxxxxxxxx> wrote: > If not too late, I'd like to discuss our security process. > Do we as the project generally agree to use responsible disclosure policy > http://en.wikipedia.org/wiki/Responsible_disclosure ? I think something like that makes sense. I'm a bit wary that we write up some complicated policy that we're not then in practice capable of executing given our level of resources. We should certainly write out some documentation though... thanks -- PMM -- To unsubscribe from this list: send the line "unsubscribe kvm" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html