• Re: Request permission to share a survey on code review in OSS security

    From Gunnar Wolf@21:1/5 to All on Fri Jul 25 19:10:01 2025
    [ Dropping the Cc: to debian-devel@lists.debian.org,
    listmaster@lists.debian.org, team@security.debian.org as one reply should
    be enough! ]

    Md Niaz Morshed dijo [Mon, Jul 21, 2025 at 09:00:00AM -0500]:
    Dear Sir/Madam,

    Good Morning. I hope you are doing well. I am a Ph.D. student at the >University of Alabama conducting an IRB-approved study titled >“Understanding Information Needs When Looking for Security Issues During >Code Review in Open-Source Software.”

    I would like to share a short, anonymous survey with members of your >developer community. Could you please advise on the appropriate way to
    share the survey—whether through a mailing list, discussion forum, or >another channel?

    Given you already mailed a mailing list, I suggest you do this same -- send
    a brief presentation of your project, describing if possible the kind of
    data you want to get from the interview and inviting the interested people
    to answer your questionnaire. That should be enough.

    I invite you to avoid cross-posting (sending a mail to different lists, as
    you did in your original one), as it's frowned upon by our community. Of course, nobody will be angry at you for not knowing our netiquette
    beforehand 😉

    Greetings,

    – Gunnar.

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)