On Mon, Aug 10, 2026 at 04:22:41PM +0200, Peter Krempa via Devel wrote:
From: Peter Krempa <pkrempa@redhat.com>
Archives (as witnessed by recent reports) hide useful information by requiring the maintainer to download the archive which may be dangerous.
Recent submissions also contained a lot of fluff inside the archives.
Instruct submitters of security issues to attach files directly instead of hiding them in an archive.
Signed-off-by: Peter Krempa <pkrempa@redhat.com> --- docs/securityprocess.rst | 4 ++++ 1 file changed, 4 insertions(+)
diff --git a/docs/securityprocess.rst b/docs/securityprocess.rst index b9fa8d9890..d1e7fcc424 100644 --- a/docs/securityprocess.rst +++ b/docs/securityprocess.rst @@ -20,6 +20,10 @@ apply to the core project. Ensure that the "**turn on confidentiality**" checkbox is selected prior to submitting the issue, to restrict visibility to project maintainers only.
+.. important:: + Only attach plain files, do not bundle files in archives without prior request + from a libvirt maintainer.
I wonder if we should be more explicit "..do not bundle files in archives (zip, tar, etc) without prior..." Either way, Reviewed-by: Daniel P. Berrangé <berrange@redhat.com> With regards, Daniel -- |: https://berrange.com ~~ https://hachyderm.io/@berrange :| |: https://libvirt.org ~~ https://entangle-photo.org :| |: https://pixelfed.art/berrange ~~ https://fstop138.berrange.com :|