[openstack-dev] [glance] [VMT] [Security] Proposal to add Brian Rosmaita to the glance-coresec team

Jeremy Stanley fungi at yuggoth.org
Thu May 12 12:35:00 UTC 2016

On 2016-05-11 23:39:58 -0400 (-0400), Nikhil Komawar wrote:
> I would like to propose adding add Brian to the team.

I'm thrilled to see Glance adding more security-minded reviewers for
embargoed vulnerability reports! One thing to keep in mind though is
that you need to keep the list of people with access to these
relatively small; I see
https://launchpad.net/~glance-coresec/+members has five members now.

While the size I picked in item #2 at
<URL: https://governance.openstack.org/reference/tags/vulnerability_managed.html#requirements >
is not meant to be a strict limit, you may still want to take this
as an opportunity to rotate out some of your less-active reviewers
(if there are any).
Jeremy Stanley

