Skip to content

Conversation

@ijwhitfield
Copy link
Contributor

This changes the stable patch format docs to reflect how we currently submit CVE fixes to the mailing list.

Please let me know your thoughts, wanted to get a PR started because this section of the docs seems to be at odds with how we currently work. Happy to change it as long as we agree on the right way to do it.

@ijwhitfield ijwhitfield requested a review from AnneCYH as a code owner February 18, 2025 23:06
Copy link

@tswhison tswhison left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This seems to affirm the common practice.

@cengiz-io
Copy link

This is what we were doing for quite a while now. Considering the number of CVE patches that we review and apply internally, I think it's fair to make this change.

#. Every **CVE** patch **must** contain a line at the beginning of the commit
message that specifies the CVE number(s) related to the patch. This must be
the first part of the body of the comment.
#. Every **CVE** patch must contain a line just before your sign-off that
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't particularly enjoy seeing a lot of bolded text in a single sentence; it distracts readers by emphasizing too many things.
But to keep things consistent I'm adding the bold back.

Suggested change
#. Every **CVE** patch must contain a line just before your sign-off that
#. Every **CVE** patch **must** contain a line just before your sign-off that

#. The cover letter **must** contain the same "BugLink" line as in the patches
themselves, when one is present.

#. CVE cover letters should have the CVE number as the subject.
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

should or must?

This changes the stable patch format docs to reflect how we currently
submit CVE fixes to the mailing list.

Signed-off-by: Ian Whitfield <[email protected]>
@ijwhitfield
Copy link
Contributor Author

Applied changed from @AnneCYH, thanks for reviewing!

@AnneCYH AnneCYH merged commit eaca028 into canonical:main Mar 12, 2025
2 of 4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants