Open Bug 627105 Opened 15 years ago Updated 3 years ago

Make the ability to add bugs to the security group easier to get

Categories

(Core :: Security, defect)

defect

Tracking

()

People

(Reporter: briansmith, Unassigned)

Details

I have noticed cases where security-related bugs (e.g. bug 627097) are being flagged "Mozilla Confidential" instead of put into the security group. My guess is that this is being done because most people don't have the ability to add a bug to the security group after it has been reported. I know I have run into this problem and so have others. I think we should grant this capability to more users (e.g. everybody with level 1 commit access), so that these bugs can be properly managed and properly evaluated by the security team.
Yeah, this is silly. People can flag bugs sec-sensitive when filing, but not later.... Anyone should be able to mark a bug sec-sensitive, imo; just not to unmark. Does that need bugzilla backend work? :(
Severity: normal → S3
You need to log in before you can comment on or make changes to this bug.