On Wed, May 27, 2015 at 08:43:14PM -0400, David A. Cafaro wrote:
True, but how long do we wait from first contact on a security
ticket
before we start the non-responsive policy? 3 pings on a ticket? 1
month after first ping on a ticket? That's the policy we need to set to
trigger a start of the non-responsive package maintainer process.
If there's an immediate security issue in a case like this, we should
follow the provenpacker process and find someone else to address it.
(And _then_ follow the normal non-responsive process if necessary.)
<
https://fedoraproject.org/wiki/Who_is_allowed_to_modify_which_packages>
--
Matthew Miller
<mattdm(a)fedoraproject.org>
Fedora Project Leader