Re: How to coordinate web team for security releases? - Mailing list pgsql-www

From Stefan Kaltenbrunner
Subject Re: How to coordinate web team for security releases?
Date
Msg-id 45C79629.5030103@kaltenbrunner.cc
Whole thread Raw
In response to Re: How to coordinate web team for security releases?  (Tom Lane <tgl@sss.pgh.pa.us>)
List pgsql-www
Tom Lane wrote:
> Stefan Kaltenbrunner <stefan@kaltenbrunner.cc> writes:
>> So to keep it really under the hood would probably be quite difficult to do.
> 
> Certainly.  We're not looking for something absolutely bulletproof, we
> just don't want to read about it on pgsql-announce before the actual
> release ;-).  Postgres isn't the sort of target that is likely to have
> blackhats tracking our anoncvs watching for interesting commits.  We
> think it's probably enough if we can keep the topic out of the public
> mailing lists until the release announcement.  Or at least, let's try
> to accomplish that before worrying about anything tighter.

That is probably a reasonable approach to the whole issue - and for the
anoncvs/buildfarm testing thing(if we want/need that even for such
patches) we could maybe look into the recent discussion on allowing
certain patches to be pulled from trusted people.
Maybe one could use that infrastructure to get basic buildfarm testing
without the need to commit to to the main public tree immediatly.
However the time gained from that might not be worth the pain ...


Stefan


pgsql-www by date:

Previous
From: Stefan Kaltenbrunner
Date:
Subject: Re: How to coordinate web team for security releases?
Next
From: Dave Page
Date:
Subject: Re: How to coordinate web team for security releases?