snoopdave opened a new pull request, #195:
URL: https://github.com/apache/roller/pull/195

   Updates the `roller-release` and `roller-security` developer skills with 
procedure changes learned while running the 6.1.6 release and its disclosure. 
Everything added is generic guidance; no case details.
   
   **roller-security**
   - Record `fix_commit` as the commit that landed on the release branch (merge 
or squash commit), not the PR head, and confirm it is an ancestor of the 
release tag before citing it.
   - Search the correspondence before stating what a reporter said; log replies 
when they arrive.
   - New *Before READY* checklist for CVE records: remove calculator-default or 
unassessed metrics, don't leave the default status as `unaffected` unless 
assessed, check the metadata used in generated emails, and compare saves by 
content because editors reorder JSON keys.
   - New *Publication sequence*: READY → send the advisory emails from the 
portal and confirm each in the list archives → add the `vendor-advisory` 
reference → ASF Security sets PUBLIC.
   - New disclosure-notice template for reporters, and sending guidance: send 
ASF list mail from an `@apache.org` address, and check drafts made by 
automation for rewritten links.
   - Pre-disclosure public text (announcements, blog posts, website) stays 
neutral, and the instructions given to whoever writes it must not reveal what 
is being withheld.
   
   **roller-release**
   - Tally binding votes against the ASF roster rather than the website 
committer list.
   - Send announcements from an `@apache.org` address and confirm them in the 
announce@ archive.
   - Promote a candidate with one `svn mv` commit from a sparse checkout of the 
repository root; follow redirects when verifying public download URLs, since 
downloads.apache.org redirects missing files to the archive.
   - Rebase website changes onto the publishing branch, preview with `content/` 
as the web root, and check the rendered HTML (Markdown tables may not be 
enabled).
   
   Checked with `skills/roller-security/scripts/check-private.sh --range 
origin/master..HEAD` (clean). The item template still parses with 
`triage-status.py`.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to