| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
|
Review requested:
|
Sorry, something went wrong.
|
Are the n-api changes here intentional? |
Sorry, something went wrong.
There was a problem hiding this comment.
Link to the repository? Or should we keep it without a link on purpose?
Also, I assume it will be a repo on nodejs-private?
Sorry, something went wrong.
There was a problem hiding this comment.
I've not created the repo yet, but a link makes sense. It should only be accessible to those who have access to private repos within the org
Sorry, something went wrong.
There was a problem hiding this comment.
@mmarchini added the link in the first reference, not sure if we need to make all references a link or not.
Sorry, something went wrong.
There was a problem hiding this comment.
Also, I assume it will be a repo on nodejs-private?
No, its a private repo in the nodejs org as I don't believe we can move issues across organizations.
Sorry, something went wrong.
There was a problem hiding this comment.
I see. The downside is that folks who have access to private repos in this org but not on the repo we usually use for security releases will have access to the issue. It's probably fine though, it only means some folks in moderation and CommComm will have access to the issue even when they don't have access to security release discussions (which is still better than keeping the issue public).
Sorry, something went wrong.
There was a problem hiding this comment.
Sorry, something went wrong.
Add process for handling premature disclosure of a security vulnerability in the public repos. Signed-off-by: Michael Dawson <mdawson@devrus.com>
There was a problem hiding this comment.
lgtm
Sorry, something went wrong.
Co-authored-by: Richard Lau <rlau@redhat.com>
Co-authored-by: Richard Lau <rlau@redhat.com>
There was a problem hiding this comment.
lgtm. I think we need to open a request on nodejs/admin to create the repository, correct?
Sorry, something went wrong.
Co-authored-by: mary marchini <oss@mmarchini.me>
|
@mmarchini good call on creating the request in admin. Here is the list: nodejs/admin#573 |
Sorry, something went wrong.
Add process for handling premature disclosure of a security vulnerability in the public repos. Signed-off-by: Michael Dawson <mdawson@devrus.com> PR-URL: #36155 Reviewed-By: Matteo Collina <matteo.collina@gmail.com> Reviewed-By: Richard Lau <rlau@redhat.com> Reviewed-By: Mary Marchini <oss@mmarchini.me> Reviewed-By: Rich Trott <rtrott@gmail.com>
Add process for handling premature disclosure of a security vulnerability in the public repos. Signed-off-by: Michael Dawson <mdawson@devrus.com> PR-URL: #36155 Reviewed-By: Matteo Collina <matteo.collina@gmail.com> Reviewed-By: Richard Lau <rlau@redhat.com> Reviewed-By: Mary Marchini <oss@mmarchini.me> Reviewed-By: Rich Trott <rtrott@gmail.com>
Add process for handling premature disclosure of a security vulnerability in the public repos. Signed-off-by: Michael Dawson <mdawson@devrus.com> PR-URL: #36155 Reviewed-By: Matteo Collina <matteo.collina@gmail.com> Reviewed-By: Richard Lau <rlau@redhat.com> Reviewed-By: Mary Marchini <oss@mmarchini.me> Reviewed-By: Rich Trott <rtrott@gmail.com>
| Back | FazBrowse Home | New Git URL |
Checklist