Re: Correctly configuring Apache Commons components for oss-fuzz

2022-11-10 Thread Oliver Chang
Hi Mark, In addition to the reasons Roman listed, the current structure also allows us to allocate more compute resources to all of these Apache packages, rather than all of them sharing the CPUs allocated for a single OSS-Fuzz "project". We can definitely ensure that secur...@commons.apache.org

Re: Correctly configuring Apache Commons components for oss-fuzz

2022-11-10 Thread Mark Thomas
Oliver, My requirements regarding configuration are: - secur...@commons.apache.org MUST be notified of all security vulnerability reports for all Apache Commons components - a mechanism MUST be provided for the secur...@commons.apache.org Google user to view all historical reports that were