huntr icon indicating copy to clipboard operation
huntr copied to clipboard

Make our process obvious to maintainers

Open JamieSlome opened this issue 3 years ago • 12 comments

Artefacts

  • [ ] Create a step by step guide
  • [ ] Place it along their path (somewhere relevant and timely)

Core Success Measures

  • [ ] Maintainer that come and don't review -50%
  • [ ] Maintainer that come and don't confirm fix -50%

Additional Success Measures

  • [ ] Maintainers notice that there is a step by step guide (15% of new maintainers click this wiki)
  • [ ] The wiki is easy to understand (6/10 find it helpful)

JamieSlome avatar May 18 '21 06:05 JamieSlome

Hi @JamieSlome, can you please groom this ticket. If we don't have a definition yet, feel free to leave it as a note until grooming.

adam-nygate avatar May 20 '21 16:05 adam-nygate

@ehuelsmann @JamieSlome do you guys still think this is necessary?

psmoros avatar Nov 11 '21 13:11 psmoros

I just checked the site (but not any security reports); the information that I need as a maintainer isn't there in a way that it allows me to find it quickly and provide me with a consistent understanding of my role in the disclusore process. I.e. there's no indication that rejected vulnerability reports will be immediately disclosed (and not stay private or archived); similarly, there's no indication that the effect of selecting a commit SHA (as a maintainer) will directly and immediately publish the vulnerability report. There's more, but maybe it's more practical to have an initial process outline published on the site after which I can comment more?

ehuelsmann avatar Nov 11 '21 20:11 ehuelsmann

Makes perfect sense! Thanks for helping us see this @ehuelsmann :))

psmoros avatar Nov 12 '21 11:11 psmoros

I've been a bit confused because I didn't know the right process to follow, so I think a guide to disclosing vulnerabilities would have been helpful

from @mcornella

psmoros avatar Nov 12 '21 12:11 psmoros

Screenshot_2021-12-08_at_14 56 36 ~ from maintainer of boxbilling

psmoros avatar Dec 08 '21 16:12 psmoros

image

psmoros avatar Dec 15 '21 16:12 psmoros

Also

https://discord.com/channels/672495759706554369/900002814158311434/920430123742797854

jaapmarcus avatar Dec 15 '21 17:12 jaapmarcus

image Thanks again @jaapmarcus you're the best!

psmoros avatar Dec 16 '21 12:12 psmoros

Sorry to anyone following this ticket, it has been mishandled. A deadline will be re-assigned at a later date.

psmoros avatar Dec 16 '21 13:12 psmoros

Screenshot 2022-01-05 at 11 25 21

It's everywhere...

psmoros avatar Jan 05 '22 11:01 psmoros

https://huntr.dev/bounties/e67603e6-8497-4ab6-b93a-02c26407d443/

psmoros avatar Jan 11 '22 13:01 psmoros