User Details
- User Since
- Nov 5 2021, 2:54 PM (159 w, 4 d)
- Availability
- Available
- LDAP User
- Unknown
- MediaWiki User
- MMartorana (WMF) [ Global Accounts ]
Mon, Nov 25
Fri, Nov 22
Thu, Nov 21
@acooper, @Cleo_Lemoisson, @sbassett or @Reedy - Could you please add @Jly to the Security Gdrive?
@Jly - I added you to acl*security_secteam, acl*security and Trusted-Contributors
Hi @Seddon - I’m wrapping up my review and haven’t found any blockers so far.
Wed, Nov 20
@acooper - For now, we have selected osv-scanner and Semgrep as the initial tools, as they address the majority of our needs across many languages for SCA and SAST in the first phase or MVP.
Tue, Nov 19
@Jly - I added you to acl*security_secteam, acl*security and Trusted-Contributors
Mon, Nov 18
@acooper or anyone with the necessary permissions, could you please add Jimmy to @security-team? I’ve already added him to @security.
Hi @CCiufo-WMF and @Jdlrobson - do you plan to address T378305 before deployment?
Fri, Nov 15
Hey @sbassett - let’s discuss further in the MR I’ll submit - it should make things clearer.
Wed, Nov 13
Mon, Nov 11
Wed, Nov 6
Hey - for the initial authn/z setup, I recommend using Django's built-in system. It's a solid, easy, and secure starting point.
Hey, this looks good as starting point.
Mon, Nov 4
Thu, Oct 31
Wed, Oct 30
Hi @CCiufo-WMF, @NBaca-WMF and team - following our meeting, I will remove this extension from our risk register since you plan to wait for our review before proceeding with deployment.
Mon, Oct 28
Hi everyone, I wanted to share an update to inform @acooper and the security team that this extension will undergo some architectural changes in the coming weeks.
Oct 23 2024
Oct 21 2024
Oct 17 2024
Hi @CCiufo-WMF and team, I understand that your plan is to deploy soon, but after some evaluation, I plan to submit my review by mid-November.
Oct 16 2024
Oct 14 2024
Oct 9 2024
After doing some research, I believe we can effectively utilize Django’s built-in capabilities for reporting and managing tabular data in our Universal Security Dashboard. Django’s ORM simplifies data querying and manipulation, while its templating system enables the rendering of tables in web views.
Oct 8 2024
Sep 27 2024
Sep 26 2024
Sep 6 2024
Done (confirmed via T373713)
Hey @jasmine_ - I have granted access to acl*security_sre .
Aug 28 2024
Aug 21 2024
Aug 16 2024
Hello, thank you for informing us. The review will be published shortly.
Jul 31 2024
Hi @tappof - I have granted access to security@wikimedia.org.
Hi @tappof - I have granted access to acl*security_sre .
Jul 25 2024
Jul 24 2024
Practical Application and Results section added: https://www.mediawiki.org/wiki/Security/Wikimedia_Risk_Calculator
Jul 23 2024
Jul 19 2024
Jul 17 2024
Issue number 2 has now successfully been addressed.
Jul 15 2024
Jul 10 2024
Supplemental announcement is out!
Jul 9 2024
A pull request for this patch has been submitted on github: https://github.com/lingua-libre/BlueLL/pull/18