Hacker News new | ask | show | jobs
by spiffxp 2755 days ago
I was part of the Kubernetes v1.13 release team, though not part of the team that produced this fix.

The project's Product Security Team adhered to the timeline indicated in the project's security release process: https://github.com/kubernetes/sig-release/blob/master/securi...

tl;dr a fix is (edit: optionally) sent out to a private distributors list under embargo within 2 weeks of disclosure, and public disclosure (with new releases) happens within 3 weeks of disclosure (with some discretion for timing to make sure it's not buried in a weekend or off-hours)

I can't speak to who knew about it when outside of the project, but I know the project acted expediently once the vulnerability was disclosed.

1 comments

I should've known that there was an official timeline as part of the process, but forgot. I wouldn't have asked about that otherwise; I didn't mean to cast any aspersions. Whatever I'm thinking of was from folks I respect, presumably about another issue or I'm simply mis-remembering things. Thank you.

(Also, aside, props to everyone that got this rolled out so fast at the major providers.)