Hi everyone,
I’d like to propose a few amendments in the security policy to handle security pull requests provided by non-committers:
- Change the title https://dev.xwiki.org/xwiki/bin/view/Community/SecurityPolicy/#HWhat2019stheprocesstohandlesecurityissuesforcommitters3F so that it address to committers or non committers
- Add a note reminding that fixing a security involve to have requested access to the security channels to be able to communicate with other developers
- Edit “Take the ownership on the security issue by assigning the JIRA ticket to yourself.” for “Assign the JIRA ticket to yourself and take the ownership or ask a committer to take the ownership by assigning the ticket”
- Move “Create a draft advisory on Github (see section below).” to step 3
- Edit step 3 (which would become step 4) with:
Fix the issue on all supported branches or propose a fix through a pull request:
the pull request should be performed from a temporary private fork associated with the draft advisory
don’t merge it from the GitHub UI (i.e. from the advisory page) because the JIRA issue title will appear in the commit log, disclosing the security issue too soon. Use these steps instead.
if the pull request is created by a non-committer, a committer should be assigned to it and should handle merging it through a cherry-pick once it’s ready
wdyt?
I’m opening this vote until monday 27th of july.
Here’s my +1