we recently worked on the Security Advisory App in order to simplify paper works when fixing security issues. This proposal is to go with the same idea of simplifying the process and not having to duplicate information.
Right now the documented process for handling a security issue specifies:
Announce the fix on the security category of the forum with the list of branches where the fix is provided and the link to the advisory
We originally put that in the process so that Sponsoring companies and interested people could follow in the forum whatās happening in terms of security fixes before the disclosure to react.
To be transparent, the top Sponsoring Company, XWiki SAS, is currently not using that channel and they are working on an automatic synchronization system to import the data from the security advisory app on XWiki.org.
Now I opened an improvment ticket for the security advisory app to allow individuals that belongs to a dedicated group to be notified when an advisory is marked announced there (see: Loading... ). IMO we probably need this to be done first before changing the policy.
But I wanted to gather opinions already on changing the process here to only have this automated notification from the application, and no more post on the forum about advisories.
Does your proposal take into account non-nominal cases?
Iām thinking for situations where we announce an issue as fixed in the forum, only to realise the next day that the fix is not the right one (e.g., it is causing regressions).
Good point I forgot this possibility. So right now it doesnāt take it into account. Honestly Iām not sure we want to have something specific for that: the idea of the announcement notif is just a notification, people have to check then how the advisory evolves and we can change its state and comment etc.
To give a bit of context, the idea of the extension is to centralize the security advisories and have automatic computation of the embargo dates. If we change the approach, you would see the information about new advisories through xwiki.org notifications (emails or alerts depending on your settings).
I do now follow the app and itās children and set mail alert. I will see how it feels. Thanks.
What I would really like: filter out all fixes made in my current version or below. This way I can see really fast the time I must have upgraded. Our hoster isnāt the fastest one, so we canāt upgrade every minor version. We have to skip some. But I really like to know when itās getting urgent for us.
You definitely donāt have to upgrade every minor version, but given that itās an intense security period (like for many open source projects these daysā¦) you should ideally make sure to stay under the CVE radar, which means upgrade at least once every 3 months (since CVEs are published 3 months after the fix is released). We generally recommend targeting an upgrade every 2 months (so that you have some margin).
Iām coming back on this: I implemented a solution in the security advisory app to trigger notifications when an advisory is announced. You can already use it by enabling the notification in your settings on www.xwiki.org: