[Secure-testing-team] Seems fixed in the wrong place

Thijs Kinkhorst thijs at debian.org
Fri May 23 09:28:54 UTC 2008


> please CC secure-testing-team at lists.alioth.debian.org in the case of a
> security related bug and if the version of that bug is also in testing.

I'm not so sure this is a good idea. We now have reportbug adding a CC
when a bug is reported with that tag, reportbug-ng being patched to do the
same, and the bts command changed so it CC's the teams when someone adds
such a tag. However, it completely misses those cases where someone just
mails submit@ or control@ directly (quite common), or any new or custom
tools that may arise.

Why don't we just reassign this bug to the BTS and have request that
changed so that it forwards those bugs to the specific place? It's the
canonical place, it's one place to change when changes are needed and it
will work regardless of which bug reporting method someone chooses.


