Files
Jeremy Stanley 4ee4367072 Double our advance notification period
I've received multiple pleas from downstream stakeholders to give
longer notice before publication, since a week can be insufficient
time to prep roll-out or package updates for complex vulnerability
fixes spanning multiple projects and services.

Increase the advance notification from 3-5 business days to 5-10
business days in order to accommodate more complicated advisories,
at the coordinator's discretion.

Note that we can't go past this if we continue to notify the private
linux-distros mailing list at the same time, since their policy is
that anything disclosed to them must also be published to the
oss-security mailing list within two weeks.

Change-Id: I12d057f357b35f62a89654226baaa6c5b83e00dd
Signed-off-by: Jeremy Stanley <fungi@yuggoth.org>
2025-11-04 22:04:28 +00:00
..
2022-07-28 09:57:33 +08:00
2014-12-01 11:27:31 +01:00
2015-03-02 09:25:55 -08:00
2024-05-01 17:06:11 -04:00