Page MenuHomePhabricator

Identify if there are changes of Wikibase Suite components that are required to be included in the security/maintenance
Closed, ResolvedPublic

Description

Excluding Mediawiki and Wikibase changes which we cover elsewhere.
We want to know what changes (likely identified by commit hashes) will be included in the ucpoming security release

We're looking primarily out for changes relevant for the security
This will be likely primarily executed by looking at the history changes (changelog/release notes if provided, VCS history elsewere) and scanning for potential severe issues being fixed.

List of components to check

  • WDQS UI
  • WDQS (will be done by asking WMF Search team by @WMDE-leszek ), including any changes to the configuration of the query service
  • Quickstatements (incl. "magnustools" library)
  • WikibaseLocalMedia

Acceptance criteria

  • Relevant versions of the affected components have been recorded in the wmde2.env file

Event Timeline

The current state of wmde2.env has the relevant version for the security release.

none the less there is a PR with the most recent versions: https://github.com/wmde/wikibase-release-pipeline/pull/237