User Details
- User Since
- Nov 5 2021, 2:54 PM (223 w, 20 h)
- Availability
- Available
- LDAP User
- Unknown
- MediaWiki User
- MMartorana (WMF) [ Global Accounts ]
Yesterday
Tue, Feb 10
Fri, Feb 6
Thu, Feb 5
Tue, Feb 3
Thanks for the ping! We’re aware of the rollout timeline.
Tue, Jan 27
Fri, Jan 23
Security Review Summary - T399459 - 2026-01-23
Wed, Jan 21
Hi @Ifrahkhanyaree_WMDE - apologies on behalf of the Security-Team. We’ve reprioritized this review and expect it to be completed by the end of this week.
Tue, Jan 20
Jan 9 2026
Email from T404620#11504513 has been sent to various mailing lists:
Jan 8 2026
Hi @Jdrewniak - to help us scope this review, could you clarify the expected deployment window more precisely ?
Jan 7 2026
Dec 16 2025
Hey cloud-services-team and @dcaro - this service has a known vulnerability. Since there are currently no mitigation steps and no identified code owner, the Security-Team strongly recommends shutting the service down.
Dec 15 2025
Dec 8 2025
Given the scope, I think it seems reasonable to start with a simple lookup table that maps known AAGUIDs to readable device names (e.g. Google Password Manager, iCloud Keychain, YubiKey 5 Series, etc...). This can be either hardcoded at first, or stored in a small static file. I think that is a good starting point rather than some more complex approach for now.
Dec 2 2025
Dec 1 2025
Hey @Petrb - based on the codepath above this still looks like a plausible SQL injection vector. Could you confirm whether you plan to patch this upstream, or if there’s anything needed from our side to help move it forward?
Nov 25 2025
Nov 17 2025
Nov 12 2025
Nov 11 2025
Hey cloud-services-team - this looks like a potential vulnerability. What mitigation approach do you want to take?
Nov 10 2025
Nov 7 2025
I’ve restored access for @Snwachukwu to WMF-NDA
Nov 3 2025
Since there hasn’t been any recent activity on this task, the Security-Team plans to close it soon due to inactivity.
Oct 27 2025
I have added @SLopes-WMF to acl*security_management .
Oct 14 2025
Hey @Miriam and @Snwachukwu - how are you?
Oct 7 2025
Hi @jsn.sherman - I have granted access to acl*security_developer .
Sep 18 2025
Sep 12 2025
Sep 9 2025
Security Review Summary - T355161 - 2025-09-09
Last commit reviewed: 1a70f4d
Aug 25 2025
From a security perspective, this is safe to deploy.
Aug 20 2025
Hey - I got access to zendesk yesterday, so this can be resolved.
Aug 4 2025
Jul 30 2025
Jul 18 2025
From a security perspective, this seems reasonable as long as it’s paired with the usual safeguards: short-lived tokens, proper key rotation, minimal claims, and good client validation guidance. It’s a common pattern across the industry.
Jul 11 2025
They all look good to me!
From a security perspective, we support moving forward with adopting CSP policies for these microsites.
Jul 9 2025
Supplemental announcement is out!