Discussion on oss-sec about size criteria for disclosures to cloud hosting providers
On the oss-sec list, participants debate which size of hosting provider should be eligible for a vulnerability disclosure initiative, with no defined criterion yet.
On 4 October 2026, a discussion on the oss-sec mailing list, republished in the feed on 5 October, raised the question of which size criteria would define the eligibility of hosting providers for a disclosure initiative. According to the automatically translated material, a participant asked where the limit lies and what minimum size should qualify.
The central point is that many smaller hosting providers exist besides the large cloud providers named, yet they are still very large. The text offers no conclusion, no list of criteria and no decision about the initiative. It records only the question and the observation.
To consult and verify, read the original message in the public oss-sec list archive (2026, fourth quarter, message 40) and compare it with the translated feed version. Confirm dates and authorship in the original before citing it.