Fold release and disclosure lessons into the release and security skills - #195
Merged
Merged
Conversation
roller-security: - Record as fix_commit the commit that landed on the release branch, not the pull request head, and confirm it is in the release tag. - Search the correspondence before stating what a reporter said, and log replies when they arrive. - Audit CVE records before READY (stray or default metrics, default status, metadata used in generated emails) and document the portal's publication sequence. - Add a disclosure-notice template and guidance for sending ASF list mail. - Keep pre-disclosure public text neutral, including the instructions given to whoever writes it. roller-release: - Tally binding votes against the ASF roster, not the website. - Send announcements from an apache.org address and confirm them in the archive. - Promote in a single svn commit, and follow redirects when verifying public download URLs. - Rebase website changes onto the publishing branch and check the rendered HTML before pushing.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updates the
roller-releaseandroller-securitydeveloper skills with procedure changes learned while running the 6.1.6 release and its disclosure. Everything added is generic guidance; no case details.roller-security
fix_commitas the commit that landed on the release branch (merge or squash commit), not the PR head, and confirm it is an ancestor of the release tag before citing it.unaffectedunless assessed, check the metadata used in generated emails, and compare saves by content because editors reorder JSON keys.vendor-advisoryreference → ASF Security sets PUBLIC.@apache.orgaddress, and check drafts made by automation for rewritten links.roller-release
@apache.orgaddress and confirm them in the announce@ archive.svn mvcommit from a sparse checkout of the repository root; follow redirects when verifying public download URLs, since downloads.apache.org redirects missing files to the archive.content/as the web root, and check the rendered HTML (Markdown tables may not be enabled).Checked with
skills/roller-security/scripts/check-private.sh --range origin/master..HEAD(clean). The item template still parses withtriage-status.py.