@todo As an security team member, I want to resolve a security issue
Steps: @todo these steps need vetting from someone(s) from the Drupal security team.
- End user (Guest) submits a private report of a possible security incident.
- Only the original reporter and members of the security team can see this report.
- Security team member performs triage to ensure validity of report, check for duplicates, etc.
-
- If invalid, send scripted "thanks but no thanks" note that refers to other resources.
-
- Report is closed.
- If valid, security team member adds relevant maintainer(s) to the issue, who now have the ability to see the information in the report and participate in discussion.
- Maintainer(s) go back and forth with security team members to arrive at a suitable solution.
- The solution is tested against the affected project in a private security testbot.
- If it passes, the solution back-ported to whatever other versions are affected.
- A security announcement (SA) is drafted and reviewed by those involved in the issue.
- On the next security window, the patches are applied and release is made.
- The release needs to be explicitly marked as "security release" so it shows up in the appropriate places (e.g. d.o/security, Update Status dashboard)
- SA is published, points to releases.
Observations:
-
✅ X -
❌ Y
Related issues:
- #1234: Blah
Edited by quiet1