git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Security mailing list & process, was Re: My summary of the Git Contributors' Summit 2026

From
Johannes Schindelin <johannes.schindelin@gmx.de>
Date
Sep 24, 2026, 12:38 UTC
Message-ID
<9dd7427b-2130-a936-5a90-24f7c8fd719f@gmx.de>
In-Reply-To
<874ifg11zc.fsf@emacs.iotcl.com>
Hi Toon,
On Wed, 23 Sep 2026, Toon Claes wrote:
Show 27 quoted lines
> Johannes Schindelin <Johannes.Schindelin@gmx.de> writes:
> 
> > Security mailing list and process
> >
> > [...]
> >
> > Microsoft's release process reportedly needs about seven weeks. There
> > were no objections in the room to proceeding without waiting for that
> > schedule. (Personal note: That release process was misrepresented,
> > which is surprising
> 
> I wouldn't say this is surprising, I think most people just don't know
> the details.
> 
> > as I coordinated two or three Git for Windows security bugfix releases
> > _on the git-security list_ since the most recent Git security bugfix
> > release, it's always the same thing: release on a second Tuesday of
> > the month, three weeks before that the patches need to have settled,
> > everybody goes home with a dependable timeline.
> 
> Well, thanks, that's clear.
> 
> Personally I think we can try to follow that schedule, if possible. We
> currently have a few patches waiting for months to be released, and
> that's not because of the Git for Windows release schedule, but more
> because the lack of call to action. Those easily can get out with the
> GfW cadence.

I'm glad that you agree that Patch Tuesday isn't all _that_ much of a friction point, this will allow some of my colleagues to relax visibly.

> [...]
> 
> So I would like to suggest you and me collaborate closely to get a next
> security release out and then we can go from there.
Excellent! Let's continue this conversation in a more private setting ;-)

Ciao, Johannes

Previous: Johannes SchindelinNext: Junio C Hamano
Message 16 of 19 in “What's cooking in git.git (Sep 2026, #08)”
  1. Junio C HamanoSep 22, 2026
  2. kh/format-patch-range-diff-notesKristoffer Haugsbakk, Sep 22, 2026
  3. Git v3.0 timeline, was Re: What's cooking in git.git (Sep 2026, #08)Johannes Schindelin, Sep 22, 2026
  4. Junio C HamanoSep 22, 2026
  5. Johannes SchindelinSep 22, 2026
  6. My summary of the Git Contributors' Summit 2026, was Re: Git v3.0 timeline, was Re: What's cooking in git.git (Sep 2026, #08)Johannes Schindelin, Sep 22, 2026
  7. Daniele SassoliSep 23, 2026
  8. D. Ben KnobleSep 23, 2026
  9. Toon ClaesSep 23, 2026
  10. Toon ClaesSep 23, 2026
  11. Junio C HamanoSep 23, 2026
  12. Junio C HamanoSep 24, 2026
  13. Junio C HamanoSep 24, 2026
  14. Johannes SchindelinSep 24, 2026
  15. Johannes SchindelinSep 24, 2026
  16. Johannes SchindelinSep 24, 2026
  17. Junio C HamanoSep 24, 2026
  18. Ramsay JonesSep 24, 2026
  19. Luca MilanesioSep 25, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.