On Sat, Jul 25, 2009 at 03:39:12PM +0100, Nicholas Clark wrote: > On Sat, Jul 25, 2009 at 12:13:04PM +0100, Dave Mitchell wrote: > > Is anyone aware of any issues that would stop me releasing 5.10.1-RC1? > > Please could you make sure that the release announcement, the INSTALL file, > and anywhere else relevant that mentions perlbug also stresses the security > bug contact address: perl5-security-report@perl.org Well, perl5-security-report is mentioned in INSTALL and the most recent perdeltas, but that's about it. Conversely, the string 'perlbug' appears in all the following places (ignoring old perldeltas): ./Configure ./configure.com ./Cross/Makefile-cross-SH ./ext/B/t/deparse.t ./ext/DynaLoader/XSLoader.pm ./ext/DynaLoader/XSLoader_pm.PL ./ext/IPC-SysV/Changes ./ext/re/re.pm ./ext/Storable/t/downgrade.t ./ext/Time-HiRes/t/HiRes.t ./.git/index ./.git/objects/pack/pack-2fe00e4a1e4b28f4fb1389611278fa1e348849bd.pack ./hints/bsdos.sh ./hints/freebsd.sh ./hints/README.hints ./INSTALL ./lib/base/Changes ./lib/constant.pm ./lib/ExtUtils/Changes ./lib/Fatal.pm ./lib/File/Find/t/find.t ./lib/Filter/Simple.pm ./lib/FindBin.pm ./lib/Locale/Maketext/ChangeLog ./lib/locale.t ./lib/Pod/Simple/t/perlfaqo.txt ./lib/Pod/Simple/t/perlfaq.pod ./lib/re.pm ./lib/Text/TabsWrap/CHANGELOG ./lib/XSLoader.pm ./makefile ./Makefile ./makefile.old ./Makefile.SH ./MANIFEST ./META.yml ./NetWare/Makefile ./patchlevel.h ./pod.lst ./pod/perlfaq2.pod ./pod/perlfaq3.pod ./pod/perlguts.pod ./pod/perlhack.pod ./pod/perllocale.pod ./pod/perl.pod ./pod/perlport.pod ./pod/perltrap.pod ./pod/perlutil.pod ./pod/perlxs.pod ./pod/roffitall ./Porting/checkAUTHORS.pl ./Porting/corelist.pl ./Porting/how_to_write_a_perldelta.pod ./Porting/makemeta ./README ./README.cygwin ./README.freebsd ./README.irix ./README.linux ./README.macosx ./README.openbsd ./README.solaris ./README.vms ./README.win32 ./t/comp/opsubs.t ./t/lib/h2ph.h ./t/lib/warnings/sv ./t/op/groups.t ./t/op/magic.t ./t/op/repeat.t ./t/op/subst.t ./t/op/tr.t ./t/README ./t/TEST ./t/test.pl ./utils/h2xs ./utils/h2xs.PL ./utils.lst ./utils/Makefile ./utils/Makefile.SH ./utils/perlbug ./utils/perlbug.PL ./vms/descrip_mms.template ./win32/Makefile ./win32/makefile.mk Rather than patching many of those files, perhaps a more feasible approach would be to patch perlbug to ask whether it is a sensitive bug report, and if so, email the report to the other address? (But not for 5.10.1). -- print+qq&$}$"$/$s$,$a$d$g$s$@$.$q$,$:$.$q$^$,$@$a$~$;$.$q$m&if+map{m,^\d{0\,},,${$::{$'}}=chr($"+=$&||1)}q&10m22,42}6:17a2~2.3@3;^2dg3q/s"&=~m*\d\*.*gThread Previous | Thread Next