On Wed, May 27, 2015 at 08:43:14PM -0400, David A. Cafaro wrote:
True, but how long do we wait from first contact on a security
before we start the non-responsive policy? 3 pings on a ticket? 1
month after first ping on a ticket? That's the policy we need to set to
trigger a start of the non-responsive package maintainer process.
If there's an immediate security issue in a case like this, we should
follow the provenpacker process and find someone else to address it.
(And _then_ follow the normal non-responsive process if necessary.)
Fedora Project Leader