HoF URL: https://security.wikimedia.org/hall-of-fame/
Some documentation: https://claire.sharkgirl.ing/security_trinklets.html
HoF URL: https://security.wikimedia.org/hall-of-fame/
Some documentation: https://claire.sharkgirl.ing/security_trinklets.html
| Subject | Repo | Branch | Lines +/- | |
|---|---|---|---|---|
| security-landing-page: deploying update | operations/deployment-charts | master | +1 -1 | |
| security-landing-page: deploying update | operations/deployment-charts | master | +1 -1 |
| Title | Reference | Author | Source Branch | Dest Branch | |
|---|---|---|---|---|---|
| Update CVEs | repos/sre/miscweb/security-landing-page!13 | mstyles | hof-update-CVE | master | |
| Fix references to Miraheze Issue Tracker on the Hall of Fame | repos/sre/miscweb/security-landing-page!12 | blankeclair | fix-task-links | master | |
| Add BlankEclair to Security Hall of Fame | repos/sre/miscweb/security-landing-page!11 | mstyles | hall-of-fame | master |
FYI, my trinklets page lists all public vulns I've found. As of writing, all but one (NeoChat) are MediaWiki extensions or skins
Yep, I think we'll include all of the MediaWiki-related ones as separate entries in the HoF, as that seems to be the tradition.
mstyles opened https://gitlab.wikimedia.org/repos/sre/miscweb/security-landing-page/-/merge_requests/11
Add BlankEclair to Security Hall of Fame
sbassett merged https://gitlab.wikimedia.org/repos/sre/miscweb/security-landing-page/-/merge_requests/11
Add BlankEclair to Security Hall of Fame
Change #1112270 had a related patch set uploaded (by Mstyles; author: Mstyles):
[operations/deployment-charts@master] security-landing-page: deploying update
Change #1112270 merged by jenkins-bot:
[operations/deployment-charts@master] security-landing-page: deploying update
Hi Security Team,
Please see https://gitlab.wikimedia.org/repos/sre/miscweb/security-landing-page/-/merge_requests/12 and in addition some of the CVEs reference the incorrect year.
Can we please show a little care and respect for a volunteer whose put a significant amount of effort into securing the Wikimedia Ecosystem?
Quite frankly, the poor management of the process behind the hall of fame and lack of review into the patch does not come across well.
Thanks,
Sam
I've approved and merged MR12, @Mstyles - can you get that deployed soon-ish?
Apologies for the errors, but we've never had to point to the confusingly-similar miraheze bug-tracker in the history of the security team hall of fame. We'll keep an eye out for those going forward. We've also removed the dated contact form. Not to sound too flippant, but managing the hall of fame is fairly low on our list of priorities and all of the other work for which we are tasked, so sometimes things like this slip. But they are pretty easily fixed.
sbassett updated https://gitlab.wikimedia.org/repos/sre/miscweb/security-landing-page/-/merge_requests/12
Fix references to Miraheze Issue Tracker on the Hall of Fame
sbassett merged https://gitlab.wikimedia.org/repos/sre/miscweb/security-landing-page/-/merge_requests/12
Fix references to Miraheze Issue Tracker on the Hall of Fame
mstyles opened https://gitlab.wikimedia.org/repos/sre/miscweb/security-landing-page/-/merge_requests/13
Update CVEs
sbassett merged https://gitlab.wikimedia.org/repos/sre/miscweb/security-landing-page/-/merge_requests/13
Update CVEs
Change #1114446 had a related patch set uploaded (by Mstyles; author: Mstyles):
[operations/deployment-charts@master] security-landing-page: deploying update
Change #1114446 merged by jenkins-bot:
[operations/deployment-charts@master] security-landing-page: deploying update