Page MenuHomePhabricator

Create an SOP for handling of Cloud/Toolforge open vulnerability issues
Open, MediumPublic


We have a number of open XSS and other vulnerability and compliance issues for Cloud VPS projects and/or Toolforge tools. We need to document and communicate what our process is for dealing with these. It's topical as some of these projects are abandoned, many are run by folks with minimal free time, folks who may need a bit of sheparding on what to do, but in the end we cannot allow applications with exploitable issues to remain online indefinitely.