Comment 9 for bug 395960

Revision history for this message
Curtis Hovey (sinzui) wrote : Re: 'private' Librarian opens us to security vulnerabilities

I think the confusion here is about importance, not the value, but the field itself. Important is severity to the user + engineer's will to address + certainty of success. The composite value is used communicate when the bug will be fixed. It is clear by the private state that this is severe, but the description hints at a lot of uncertainty, which I attribute to why the bug was not address sooner.

This new information shows certainty has changed, but that it is not enough to influence will. I think Gary is staying that while we are know how to fix it, the fix requires more time than he can allocate in the near future because more important issues.