Let distro maintainers or trusted persons see security issue count in dependent modules

Created on 18 November 2013, over 11 years ago
Updated 1 April 2025, 5 days ago

Problem/Motivation

Distros contain contrib modules and distro maintainers often have testing and other procedures they must work through before releasing a new distro version. When a security update for a dependent module is released they may have to rush that process and risk making a mistake. Knowing of an impending security release will for better planning.

Proposed resolution

Let distribution maintainers see count of s.d.o issues for modules and statuses for modules in their distro so that they can plan better for new releases of their distro.

This would be exposed only for modules in a distro and to the maintainer(s) of that distro.

This would show only issue counts, not the issue title or other details of the issues. Perhaps issue status and perhaps followup date.

To mitigate against someone creating a distro of every Drupal module this could be enabled per s.d.o account (perhaps with a role) so that only "trusted" distro maintainers have access to this.

Remaining tasks

Possible tasks:

  1. Get a count of issues for a status for a module
  2. Figure out how to get each of those counts for the modules in a distro
  3. Make a view that will be available for a user who is a maintainer of a distro
  4. Make this a per-user or per-role feature
✨ Feature request
Status

Closed: outdated

Version

1.0

Component

Code

Created by

πŸ‡ΊπŸ‡ΈUnited States coltrane

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

  • πŸ‡ΊπŸ‡ΈUnited States greggles Denver, Colorado, USA

    I feel like the initial motivation for this concept has fallen away.

    The most sustainable thing at this point is that maintainers of distributions (or recipes) that are successful should become co-maintainer of the modules in their distribution/recipe.

Production build 0.71.5 2024