[prev in list] [next in list] [prev in thread] [next in thread] 

List:       owncloud
Subject:    Re: [owncloud-user] Best way to be passively (push) informed of security advisories and vulnerabilit
From:       Jos Poortvliet <jospoortvliet () gmail ! com>
Date:       2015-12-20 16:43:43
Message-ID: 1788398.g2ocxeBbop () s9laptop ! jos
[Download RAW message or body]

[Attachment #2 (multipart/signed)]


On Wednesday 02 December 2015 10:52:42 miguel.telleria@iteisa.com wrote:
> Dear OwnClouders,
> 
> I would like to have a "push method" to be informed about the appearance
> of new security advisories for OwnCloud.
> 
> So far I have only been able to find a "pull method" which would be:
> 
> -  Visiting https://owncloud.org/security/advisories/
> 
> and a "low level push method" which would be watching the Github
> repository:
> 
> -  https://github.com/owncloud/security-advisories
>     (and from there go to the site or the commit to obtain more info).
> 
> I would like to ask you if there are  better ways (even through RSS,
> Twitter or mailing list) to automatically obtain the security advisories
> (or even vulnerability notices) with all its official information.

We wait approximately 14 days after we published an update with publicizing 
advisories. Though they don't get the patches any sooner, customers do get a 
'push style notification', as you say, when the patches are available and we'd 
work with them on mitigation and stuff if needed.

> Of course I am looking only for the urgent security information,
> filtering other aspects such as use cases, releases or other community
> info.
> 
> Thanks and congratulations for this great project.
> 
> Regards,
> 
> --
> 
>   Miguel TELLERĶA DE ESTEBAN
>   Responsable de Sistemas
>   www.iteisa.com · twitter.com/iteisa · fb.com/iteisa
> 
> _______________________________________________
> User mailing list
> User@owncloud.org
> http://mailman.owncloud.org/mailman/listinfo/user

-- 
Disclaimer:
Everything I do and say is based on my view of the world today. I am not 
responsible for changes in the world, nor my view on it. Everything I say is 
meant in a positive and friendly way, unless explicitly stated otherwise.
find me on blog.jospoortvliet.com

["signature.asc" (application/pgp-signature)]

_______________________________________________
User mailing list
User@owncloud.org
http://mailman.owncloud.org/mailman/listinfo/user


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic