dev:security
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| dev:security [2015/03/12 16:26] – security team relaunch gmcharlton | dev:security [2023/06/01 13:22] (current) – [How are security fixes released?] master to main dyrcona | ||
|---|---|---|---|
| Line 4: | Line 4: | ||
| You can report a security-related issue in Evergreen via the bug tracking system at https:// | You can report a security-related issue in Evergreen via the bug tracking system at https:// | ||
| + | |||
| + | While we prefer that security bugs be reported via Launchpad, they can also be reported to [[mailto: | ||
| NOTE: If you are an active Evergreen "bug wrangler" | NOTE: If you are an active Evergreen "bug wrangler" | ||
| Line 28: | Line 30: | ||
| ====How are security fixes released? | ====How are security fixes released? | ||
| - | After testing, the code will be merged to the relevant public Evergreen branches (origin/master, origin/ | + | After testing, the code will be merged to the relevant public Evergreen branches (origin/main, origin/ |
| ====How are security releases announced? | ====How are security releases announced? | ||
| Line 54: | Line 56: | ||
| Membership applications may be made by contacting one of the current | Membership applications may be made by contacting one of the current | ||
| security team members; a list of the current members' | security team members; a list of the current members' | ||
| - | maintained on the Evergreen wiki. | + | maintained on the Evergreen wiki. |
| Violations of the promises in (2) and (3) may result in immediate | Violations of the promises in (2) and (3) may result in immediate | ||
| Line 72: | Line 74: | ||
| restricted resources in order to carry out their work: | restricted resources in order to carry out their work: | ||
| - | * membership in the private security group on LaunchPad, which will allow them to see and | + | * membership in the private security group on LaunchPad, which will allow them to see and act on bugs that are marked as private security bugs |
| * a subscription and access to the private archives of the open-ils-security mailing list | * a subscription and access to the private archives of the open-ils-security mailing list | ||
| * access to the Git repositories hosting security patches in progress. | * access to the Git repositories hosting security patches in progress. | ||
| + | |||
| + | ==== Current security team members ==== | ||
| + | |||
| + | * Thomas Berezansky | ||
| + | * Galen Charlton | ||
| + | * Jeff Davis | ||
| + | * Bill Erickson | ||
| + | * Jeff Godin | ||
| + | * Rogan Hamby | ||
| + | * Kathy Lussier | ||
| + | * Mike Rylander | ||
| + | * Dan Scott | ||
| + | * Chris Sharp | ||
| + | * Ben Shum | ||
| + | * Jason Stephenson | ||
| + | * Yamil Suarez | ||
| + | * Dan Wells | ||
| + | * Liam Whalen | ||
dev/security.1426191984.txt.gz · Last modified: 2022/02/10 13:34 (external edit)