- π«π·France prudloff Lille
I agree this would be useful.
We sometimes report vulnerabilities to upstream libraries used in contrib and having a SECURITY.md file helps a lot. So we should also make it easy for people outside of Drupal to share vulnerabilities with us. - First commit to issue fork.
- π³πΏNew Zealand quietone
Keep in mind there is existing documentation, https://www.drupal.org/docs/develop/issues/issue-procedures-and-etiquett... β . Should core just link to that? Just a thought.
- πΊπΈUnited States nicxvan
nicxvan β changed the visibility of the branch 9.2.x to hidden.
- πΊπΈUnited States nicxvan
nicxvan β changed the visibility of the branch 3094817-add-a-security.md to hidden.
- π³πΏNew Zealand quietone
There is a suggested change on the MR.
Also the text limits this to core and contributed modules where as the linked page states "module, theme, or distribution".
- πΊπΈUnited States nicxvan
Thanks! I think those notes came after RTBC and I missed them.
I think I've address their comments and yours. - π³πΏNew Zealand quietone
This time I did more research before commenting.
- πΊπΈUnited States nicxvan
I think quietone addressed your suggestion, thank you!
- πΊπΈUnited States smustgrave
Distribution aren't really a thing anymore, are they?
They may be out of date with recipes but believe they are definitely still around
Sorry for the late comment here, but there already exists text of this policy β :
# How to report a security issue
If you discover or learn about a potential error, weakness, or threat that can compromise the security of Drupal, we ask you to keep it confidential and submit your concern to the Drupal security team.
Should we not use the same?
- πΊπΈUnited States nicxvan
No, that was already suggested and addressed by @quietone:
From the MR:
I don't think this is an improvement. Previous comments have pointed out that the capitalization of Contributed is incorrect. That would also apply to 'Core'. This also removes distribution, which should remain. And core does not use the style 'we ask' in any user facing text so this should not as well. The exchange of 'security vulnerability' for a list of items is limiting and I would rather that the more open to interpretation phrase remain.
We are also linking to the resource that the one you linked to links to so it's more direct.
I think it's ok to restore status since this question was addressed already.
-
quietone β
committed 8c2ce13d on 10.4.x
Issue #3094817 by nicxvan, quietone, prudloff: Add a SECURITY.md...
-
quietone β
committed 8c2ce13d on 10.4.x
-
quietone β
committed 0cf21013 on 10.5.x
Issue #3094817 by nicxvan, quietone, prudloff: Add a SECURITY.md...
-
quietone β
committed 0cf21013 on 10.5.x
-
quietone β
committed 3b8c1839 on 10.6.x
Issue #3094817 by nicxvan, quietone, prudloff: Add a SECURITY.md...
-
quietone β
committed 3b8c1839 on 10.6.x
-
quietone β
committed 74a477bc on 11.1.x
Issue #3094817 by nicxvan, quietone, prudloff: Add a SECURITY.md...
-
quietone β
committed 74a477bc on 11.1.x
-
quietone β
committed 04bd2f9c on 11.2.x
Issue #3094817 by nicxvan, quietone, prudloff: Add a SECURITY.md...
-
quietone β
committed 04bd2f9c on 11.2.x
-
quietone β
committed 6603a36d on 11.x
Issue #3094817 by nicxvan, quietone, prudloff: Add a SECURITY.md...
-
quietone β
committed 6603a36d on 11.x
- π³πΏNew Zealand quietone
Thanks everyone.
Backported to Drupal 10 because of the expectation this file exist is growing and security issues can be critical.
@nicxvan re #28, not everything in that comment was addressed. I guess recipes donβt count? IMO this text shouldnβt cite specific project types.
- πΈπ°Slovakia poker10
I agree that we technically cover all code on git.drupalcode.org, if the project is opted into security advisory coverage and has stable release. So also recipes (https://new.drupal.org/browse/recipes) and general projects ( https://www.drupal.org/project/project-general β ).
We probably need to update the wording in https://www.drupal.org/docs/develop/issues/issue-procedures-and-etiquett... β , but in the SA policy ( https://www.drupal.org/drupal-security-team/security-advisory-process-an... β ), the project types (modules, themes, distributions) are not explicitly mentioned and the policy is not restricted to these types.
- π«π·France prudloff Lille
It is now displayed here: https://github.com/drupal/drupal/security