the top sponsoring company of the project, XWiki SAS (which is also my employer for transparency) and more specifically their Support Team requested me a technical user access for the Security Advisory App installed on www.xwiki.org.
The reason is to have some automation for them to be notified of the Security Advisory App entries to act on them. On the long run it could allow us to improve the process and stop having to notify systematically on the forum security category.
For now I created a dedicated user on www.xwiki.org called XWikiSASSupport and I granted that user access to the security advisories.
I think we need to discuss this more generally and decide who is allowed to have such a technical user. Basically answer the question: Can anyone already on the security channels request one?
The big issue I see is that ATM we ask every individual to ask for access because we want to know who they are, etc. This is a big change since it means replacing individuals by a company (and we don’t know who are in this company and who will see our security issues).
We can’t ask anymore an individual to say:
I consent that I won’t publicly disclose the non-public security information that I’ll have access to, before the XWiki committers make it public, and more generally I agree to follow the rules defined in the security policy at https://dev.xwiki.org/xwiki/bin/view/Community/SecurityPolicy/
For a company we need someone with the authority to represent the whole company to say this. This makes it harder and I don’t know how we should approach it (ask for some signed doc, similar to a CLA and CCLA for companies?).
Then we would need to document the outcome in the governance probably (and/or in the security policy).
Yes, right now I would say we should probably limit that to Sponsoring Companies.
An idea would be that a Sponsoring Company would automatic get the grant to get such technical user for same reasons mentioned above: have some automation regarding the security issues published. And we would indeed list those companies in the security policy for transparency.
Now for the document to sign regarding not disclosing stuff, I really don’t know either how to approach this.