On Sat, Feb 24, 2024 at 02:07:15PM -0700, Bob Proulx wrote: > > I see that nothing more has happened on this issue since then. My bad > that I have been busy with other things and not driving on this issue. > > What's the plan to address the security vulnerability by having this > private directory in the public directory area? That's something that > needs to be fixed. Otherwise it will always be a source of errors > making private data public. And trying to keep it private will be an > endless wack-a-mole of trying to block it.
I'm not sure why. the permissions will prevent anonymous access. that's what Savannah has always done with CVS directories of private groups.
signature.asc
Description: PGP signature