Security Policy: Stop announcing advisories on the forum

Hi everyone,

we recently worked on the Security Advisory App in order to simplify paper works when fixing security issues. This proposal is to go with the same idea of simplifying the process and not having to duplicate information.

Right now the documented process for handling a security issue specifies:

Announce the fix on the security category of the forum with the list of branches where the fix is provided and the link to the advisory

We originally put that in the process so that Sponsoring companies and interested people could follow in the forum what’s happening in terms of security fixes before the disclosure to react.

To be transparent, the top Sponsoring Company, XWiki SAS, is currently not using that channel and they are working on an automatic synchronization system to import the data from the security advisory app on XWiki.org.

Now I opened an improvment ticket for the security advisory app to allow individuals that belongs to a dedicated group to be notified when an advisory is marked announced there (see: Loading... ). IMO we probably need this to be done first before changing the policy.

But I wanted to gather opinions already on changing the process here to only have this automated notification from the application, and no more post on the forum about advisories.

WDYT?

+1

Thanks! I’m all for simplifying the process.

Does your proposal take into account non-nominal cases?
I’m thinking for situations where we announce an issue as fixed in the forum, only to realise the next day that the fix is not the right one (e.g., it is causing regressions).

Good point I forgot this possibility. So right now it doesn’t take it into account. Honestly I’m not sure we want to have something specific for that: the idea of the announcement notif is just a notification, people have to check then how the advisory evolves and we can change its state and comment etc.

Hi.

I don’t know the Security Advisory App. I’m in the forum every day nearly. So this is working right now. But I’m okay to test something new.

So it’s an extension installed in xwiki.org and you can browse here: https://www.xwiki.org/xwiki/bin/view/SecurityAdvisoryApplication/ I just gave you the proper right so you should be able to see the entries.

To give a bit of context, the idea of the extension is to centralize the security advisories and have automatic computation of the embargo dates. If we change the approach, you would see the information about new advisories through xwiki.org notifications (emails or alerts depending on your settings).

I do now follow the app and itā€˜s children and set mail alert. I will see how it feels. Thanks.

What I would really like: filter out all fixes made in my current version or below. This way I can see really fast the time I must have upgraded. Our hoster isnā€˜t the fastest one, so we canā€˜t upgrade every minor version. We have to skip some. But I really like to know when itā€˜s getting urgent for us.

You definitely don’t have to upgrade every minor version, but given that it’s an intense security period (like for many open source projects these days…) you should ideally make sure to stay under the CVE radar, which means upgrade at least once every 3 months (since CVEs are published 3 months after the fix is released). We generally recommend targeting an upgrade every 2 months (so that you have some margin).

1 Like

You should probably follow Loading... then since I think it’s covering your UC

1 Like

Hi everyone,

I’m coming back on this: I implemented a solution in the security advisory app to trigger notifications when an advisory is announced. You can already use it by enabling the notification in your settings on www.xwiki.org:

The notification is triggered when the advisory handler click on ā€œannounceā€ after completed for info.

So I’m going to open a vote for changing the process.

1 Like