[security-sig][cinder] propose vulnerability:managed tag for os-brick
I've posted a patch to add the 'vulnerablity:managed' tag to the os-brick library: https://review.opendev.org/c/openstack/governance/+/794680 I just want to give a heads-up to the OpenStack Vulnerablity Management Team, since this will impact the VMT, though hopefully not very much. The Cinder team was under the impression that the VMT was already managing private security bugs for os-brick. The issue may not have come up before because usually there's a driver + connector involved and the bug gets filed under cinder (which is already tagged vulnerablity:managed). In any case, the cinder team discussed this at our recent midcycle meeting and decided that we appreciate the extra eyes and long-term perspective the VMT brings to the table, and we'd like to formalize a relation between the VMT and the os-brick library. cheers, brian
On 2021-06-04 09:52:06 -0400 (-0400), Brian Rosmaita wrote: [...]
I just want to give a heads-up to the OpenStack Vulnerablity Management Team, since this will impact the VMT, though hopefully not very much. [...]
Thanks! We loosened up the requirements well over a year ago with https://review.opendev.org/678426 in hopes more projects would check whether their deliverables met the requirements and formally enlist our assistance, but so far there's been little uptake there. -- Jeremy Stanley
participants (2)
-
Brian Rosmaita
-
Jeremy Stanley