project icon indicating copy to clipboard operation
project copied to clipboard

Shutdown `[email protected]` mailing list and migrate to GitHub Security Advisories

Open AkihiroSuda opened this issue 1 year ago • 3 comments

The [email protected] mailing list is full of spams and almost completely useless.

Can we shutdown the list and just migrate to GitHub Security Advisories (https://github.com/containerd/containerd/security/advisories/new)?

People who strongly refuse to (or who are not allowed to) create an account on GitHub may still directly reach out to the Core Committers via email or other communication methods to report vulnerabilities.

AkihiroSuda avatar Aug 14 '24 21:08 AkihiroSuda

Maybe we can clarify that we prefer GHSA without completely removing the mailing list? There can still be use-cases for the mailing list such as attachments, which don't work as well in the GHSA report flow.

samuelkarp avatar Aug 14 '24 21:08 samuelkarp

Maybe we can clarify that we prefer GHSA without completely removing the mailing list? There can still be use-cases for the mailing list such as attachments, which don't work as well in the GHSA report flow.

It is quite painful to continuously watch the list that is mostly full of spams. So I suggest completely shutting down the list.

For attachment they can use private gist, etc., or maybe just uuencode it.

AkihiroSuda avatar Aug 14 '24 21:08 AkihiroSuda

+1 for updating the security doc to remove suggesting reporting to [email protected]. It potentially leaves the project vulnerable as messages there are easily missed due to the spam. We can just update our security doc though, we don't need to take any action to shut the mailing list down.

dmcgowan avatar Aug 15 '24 23:08 dmcgowan