Elektrine lite

← Feed

@thesamesam@social.treehouse.systems

Post #2040176

2026-05-04 13:15 UTC

Why are Xen security issues allowed to retain their security marking in commit messages, like in https://cdn.kernel.org/pub/linux/kernel/v7.x/ChangeLog-7.0.3 ?

Replies (1)

  • @thesamesam@social.treehouse.systems The Xen-related code in Linux is maintained by the Xen Project. Xen has a completely separate process for handling vulnerabilities, and also keeps vulnerabilities under embargo until patches are available. Therefore, pointing out the security marking in the commit message is safe and logical.

    Open ##2471525