-
Notifications
You must be signed in to change notification settings - Fork 66
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Make embargo policy more explicit #185
Conversation
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: ritazh The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
private-distributors-list.md
Outdated
prior to the embargo lift date if users do not have direct access to the binary. | ||
|
||
However, a fully-hosted patched NON_API_SERVER_COMPONENT can be deployed | ||
prior to the embargo lift date if all users of the environment are internal to the |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
prior to the embargo lift date if all users of the environment are internal to the | |
prior to the embargo lift date only if all users of the environment are internal to the |
Not sure on the suggestion I'm proposing but do we want to make this a little more strongly worded? Is the scope of "environment" just the cluster?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Hmm, yes? Not sure on wording either.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
updated to only if all users with access to the components are internal to the Kubernetes distributor
lmk wyt
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Minor stuff.
Signed-off-by: Rita Zhang <rita.z.zhang@gmail.com>
/lgtm |
As discussed in SRC meeting, updating the embargo policy to explicitly call out embargo date guidelines and distributions need to wait until after public CVE announcement.