-
Notifications
You must be signed in to change notification settings - Fork 11
stable-patch-format: Update CVE number requirements #60
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
tswhison
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This seems to affirm the common practice.
|
This is what we were doing for quite a while now. Considering the number of CVE patches that we review and apply internally, I think it's fair to make this change. |
| #. Every **CVE** patch **must** contain a line at the beginning of the commit | ||
| message that specifies the CVE number(s) related to the patch. This must be | ||
| the first part of the body of the comment. | ||
| #. Every **CVE** patch must contain a line just before your sign-off that |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I don't particularly enjoy seeing a lot of bolded text in a single sentence; it distracts readers by emphasizing too many things.
But to keep things consistent I'm adding the bold back.
| #. Every **CVE** patch must contain a line just before your sign-off that | |
| #. Every **CVE** patch **must** contain a line just before your sign-off that |
| #. The cover letter **must** contain the same "BugLink" line as in the patches | ||
| themselves, when one is present. | ||
|
|
||
| #. CVE cover letters should have the CVE number as the subject. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
should or must?
This changes the stable patch format docs to reflect how we currently submit CVE fixes to the mailing list. Signed-off-by: Ian Whitfield <[email protected]>
|
Applied changed from @AnneCYH, thanks for reviewing! |
This changes the stable patch format docs to reflect how we currently submit CVE fixes to the mailing list.
Please let me know your thoughts, wanted to get a PR started because this section of the docs seems to be at odds with how we currently work. Happy to change it as long as we agree on the right way to do it.