@mmartorana As this was requested by @acooper and @Jcross on Dec. 5th and should not take very long, we are wondering where we are on this task list. The original suggestion to use existing scoring was erroneous but not essential or a blocker. Please update. @Cleo_Lemoisson tagged to follow up please.
- Queries
- All Stories
- Search
- Advanced Search
- Transactions
- Transaction Logs
Advanced Search
Jan 3 2024
Dec 1 2023
Hi, sorry for the delay on this. Aranya does require production shell access and we'd like to keep her in the analytics-priveatedata-users group if it's not too much trouble. Thank you! @BTullis
Mar 21 2023
Approved
Mar 3 2023
I am the contract contact person, and the end date can be listed as June 30, 2023. Thanks!
Mar 2 2023
Approved
Jan 31 2023
Thank you so much for the quick reply. Exciting!!
Jan 30 2023
Hi @BBlack and @Vgutierrez - could you please provide an update or some guidance around your expected timeline for this? Please let us know if anything else is required on our end. Thanks!
Dec 20 2022
HI @WMDE-leszek, my apologies but due to some unexpected resourcing issues we expect to complete this before the end of January. Again, we are sorry for the delay and will do our best to turn this out as soon as possible after the holiday break.
Dec 19 2022
Approved
Nov 28 2022
Nov 23 2022
Approved
Approved
Jul 15 2022
Jul 11 2022
You have the +1 from me to give access. I see no problem here.
Hey @Ottomata , could we possible have the files related to T299315: Automated attempts to log into a Phab account transmitted to us securely and then that and the rest can be deleted?
Nov 23 2021
@Jelto You have my approval as Manfredi's manager.
Nov 3 2021
@RLazarus You have my approval
Jul 28 2021
Jun 11 2021
Assigning to @Dsharpe and moving to Security Team incoming for triage and review.
May 17 2021
After reviewing the initial intent of this ticket, I believe that this plan no longer fits in with the direction we are taking with our overall intake process.
@Aklapper that's an intentionally vague reference to various improvements we need to make as a team both in and out of phab.
May 4 2021
Hi @Urbanecm_WMF - can you please let us know what your target deployment date is? It will help us to resource this appropriately. Please know that next quarter (Q1) would be the soonest we'd be able to get you in queue for review. Thank you!
Apr 21 2021
Thanks, @ori . These assumptions sound correct to us and make a beta deployment for this extension low risk. While the Security Team is not in the business of giving thumbs up/thumbs down approvals, low risk is automatically accepted by the Foundation thus unblocking beta deployment. I hope this is helpful and helps you to move forward with the project.
Apr 20 2021
Apr 19 2021
This won't be revisited until related upstream workflows are addressed.
@sbassett we have a pile of these without tasks, boards, or members. We're aware and incorporating into workflow changes / development. Expect a team review of it all...eventually.
Apr 15 2021
Thank you for doing this work, we appreciate your efforts in trying to get this extension to production. Unfortunately, the Security team is unable to assign a risk rating based upon a review not performed by a member of the Security team or an approved vendor.
Apr 14 2021
Sending over to @Dsharpe as a supplier assessment. David, please let me know if we should send these your way via some other workflow?
@Volker_E @Jdlrobson Please respond to our previous message by April 20 or we will need to move this to our backlog. Thanks!
Apr 13 2021
Apr 8 2021
@ori We will discuss at our next AppSec scrum and provide an update next week. Thanks!
Apr 6 2021
Apologies for the lack of updates @Jdlrobson - we do have a vendor lined up to complete this and will be in touch as they move forward. Thank you for your patience.
Mar 2 2021
Mar 1 2021
Hi, just a quick reminder that, as mentioned above, we will be unable to prioritize and schedule a security review until we've received an intended production support plan, including any potential Foundation team sponsorship. Please review our SOP for details: https://www.mediawiki.org/wiki/Security/SOP/Security_Readiness_Reviews
Hi @SLien_WMF - we'd love to schedule a quick chat to clarify. Could you please email me and let me know who would attend, and I will get something scheduled? Thanks!
Feb 19 2021
@CKoerner_WMF Looks like we are all set for now and @Reedy expects to finish next week. Have a great weekend :)
Feb 18 2021
Feb 11 2021
Feb 10 2021
Hi @MBinder_WMF - I noted that we still had it marked "Needs Triage" and wanted to correct that error. Adjust priority as needed. There is discussion happening around the remaining question and it was raised again just yesterday. We'll pursue resolution for you as soon as possible and apologize for the delay.
Feb 9 2021
We are untagging as there is currently no path to production that we are aware of. Should this change, please feel free to tag us back in and we will triage.
We are untagging as there is currently no path to production that we are aware of. Should this change, please feel free to tag us back in and we will triage.
We are untagging as there is currently no path to production that we are aware of. Should this change, please feel free to tag us back in and we will triage.
Untagging as there has been no activity. Please feel free to re-tag if this moves forward and we will be happy to triage.
Sending to @Dsharpe for vendor assessment
Untagging as there has been no activity. Please feel free to re-tag if this moves forward and we will be happy to triage.
Feb 8 2021
@SBisson @sbassett I'll place in planning queue for Q4 (https://phabricator.wikimedia.org/tag/secscrum/) and we'll be in touch if anything changes / is of concern. Thanks!
Feb 5 2021
@bd808 we have placed you in queue for next quarter, with work expected to begin in May for a late June launch date. Please note that all relevant code should be in a production-ready state (close to deployment with low volatility) to maintain this estimated timeline per our SOP: https://www.mediawiki.org/wiki/Security/SOP/Security_Readiness_Reviews
Feb 2 2021
Feb 1 2021
Hi @bd808 - thank you for submitting this early! We will review in our call tomorrow and be in touch with any questions or concerns we have about getting you in queue.
Jan 25 2021
Jan 22 2021
Jan 21 2021
Hi @AnneT -as we mentioned in our call, we're revamping our scheduling process a bit to provide more clarity and transparency around our workload management and prioritization process. You'll see that we've placed you into queue for this quarter: https://phabricator.wikimedia.org/tag/secscrum/ and @sbassett or @Reedy will be in touch with any questions or concerns. Thanks for your patience, and please feel free to reach out at any time!
Jan 14 2021
Jan 5 2021
Hi @AnneT - we're in the process of finalizing our queue for Q3 and we're wondering if you can let us know how close this is to production ready/what your timeline is? Thank you!
Hi @Jdlrobson - we're revamping our scheduling process a bit to provide more clarity and transparency around our workload management and prioritization process. You'll see that we've placed you into queue for this quarter, and will do our best to meet your target deployment date: https://phabricator.wikimedia.org/tag/secscrum/ and @sbassett or @Reedy will be in touch with any questions or concerns. Thanks for your patience as we work through this, and please feel free to reach out at any time!
Jan 4 2021
Hi @CKoerner_WMF - we're revamping our scheduling process a bit to provide more clarity and transparency around our workload management and prioritization process. You'll see that we've placed you into queue for this quarter: https://phabricator.wikimedia.org/tag/secscrum/ and @sbassett or @Reedy will be in touch with any questions or concerns. Thanks for your patience as we work through this, and please feel free to reach out at any time!
Nov 25 2020
@DannyS712 I've just spoken with @Reedy and at this point "by the end of the quarter" is what we are in a position to commit to. We appreciate that the grant was scheduled for the end of November, but I'm afraid we are still limited by pandemic resourcing, such as it is.
Nov 16 2020
@Aklapper what magic did you work? I just got 5 verification emails :)
Thanks so much for working on this. When you get to step #5 above - where you receive an email to the new address? I never get that email.
Nov 10 2020
@JTannerWMF - we've taken a look and would appreciate it if you would fill out the Security Readiness Review form. Thanks!
Nov 9 2020
@Aklapper I am seeing both -ctr as primary and jcross as added but needing verification. I've clicked "verify" several times over several days and never received anything.
Nov 4 2020
Hi @nnikkhoui - we were told that you are the new contact for both this ticket and https://phabricator.wikimedia.org/T257734. We're wondering if there are any changes we need to know about and whether you have a new deployment timeline? Thanks so much.
Hi @CKoerner_WMF - we just wanted to touch base as this is noted as a November target deployment date. With all of the holidays this month and a somewhat reduced capacity, we are looking to complete this towards the end of the month. We hope that works for your timeline?
HI @MusikAnimal - we've had a few bumps in the road recently and we do plan to complete it this quarter. We'll be in touch with any questions or concerns and we apologize for the delay.
Oct 28 2020
Hi @Tchanders - we've moved this ticket to In Progress and I believe we are planning on having feedback for you in the next two weeks. Please let us know if you have any questions as we move forward. Thanks!