+1. We can run queries for security issues, but that requires a more proactive 
stance than (at least some of us) honestly have. Send a note to the list 
mentioned…we don’t bite. :)

John

> On Jun 10, 2015, at 5:20 AM, David Nalley <da...@gnsa.us> wrote:
> 
> Any chance we can get Glenn to follow our security vulnerability
> reporting procedure?
> https://cloudstack.apache.org/security.html
> 
> The issue with creating 'private Jiras' is that no one gets notified.
> Indeed, this email is the first notice that any of us have about these
> issues.
> 
> --David
> 
> On Wed, Jun 10, 2015 at 4:22 AM, Wilder Rodrigues
> <wrodrig...@schubergphilis.com> wrote:
>> Hi all,
>> 
>> Our colleague Glenn reate some security issues under the ACS Jira with 
>> private visibility. I would like to have a look at those issues, but 
>> unfortunately I do not have access even to browse those.
>> 
>> How could we get that solved? Is that possible to give me access?
>> 
>> Thanks in advance.
>> 
>> Cheers,
>> Wilder

Reply via email to