Community coordination for embargoed security updates - 2026-01-21 @RedHatOpen
Community coordination for embargoed security updates - 2026-01-21  @RedHatOpen
Uploaded August 2026 | Updated September 2026, 5 hours ago
Community coordination for embargoed security updates

This is an auto-generated summary of the FRCL call on 2026-01-21:

The meeting, which included Jeremy West, Davide Cavalca, Brendan Conoboy, Neal Gompa (Conan Kudo), Michel Lind, Joanna Smith, Pat Riehecky, Aleksandra Fedorova, David Duncan, and Steve Milner, focused on two main issues: establishing clear contact for security embargoes and addressing the burden of excessive, low-quality automated CVE reports filed against Fedora. Participants discussed the difficulties with using ticketing systems for high-level contact and the need for public communication channels, while Jeremy West mentioned that Red Hat is improving incident handling, including proactive outreach, driven by the Cyber Resiliency Act. Regarding bug reports, participants confirmed the high volume of automated CVE bugs from Red Hat security is often "noise," and Jeremy West noted that Red Hat is willing to align with any policy Fedora adopts to filter CVEs, such as the RHEL approach of only prioritizing reports with a CVSS base score greater than 7.0.

The participants agreed on two key next steps: documenting the 24/7 Red Hat security contact, "secalert at red hat.com," for embargoed issues, which Steve Milner volunteered to coordinate for both CentOS and Fedora, and bringing the discussion regarding a new CVE filing policy before Fesco, which Vítězslav "Víšek" Král volunteered to do.

Jira Epic: redhat.atlassian.net/browse/FRCL-12
Gemini AI Summary: docs.google.com/document/d/1z0y1zTnWetd725yMml1qoLYTdEIuLFSK4zLluymmbIg/edit?usp=meet_tnfm_calendar
Community coordination for embargoed security updates - 2026-01-21Open Source and Business ModelsSecure Container Supply Chains DiscussionRed Hat NEXT! 2022: The Evolution of ComputePost-Flock 2026 Roundup - 2026-06-24Community Central: Performance Co-PilotUpstream: A Conversation about the Foreman ProjectCommunity Central: Intro to Ceph: Open Source Distributed Storagellm-d 101: Why Do We Need It?Red Hat NEXT! 2022: Enabling Next Generation Networking with eBPFWhy AI Infrastructure Must Be Built in the OpenGetting Started with Inference Using vLLM
Red Hat Open |

Community coordination for embargoed security updates - 2026-01-21

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER