snoopdave opened a new pull request, #195: URL: https://github.com/apache/roller/pull/195
Updates the `roller-release` and `roller-security` developer skills with procedure changes learned while running the 6.1.6 release and its disclosure. Everything added is generic guidance; no case details. **roller-security** - Record `fix_commit` as the commit that landed on the release branch (merge or squash commit), not the PR head, and confirm it is an ancestor of the release tag before citing it. - Search the correspondence before stating what a reporter said; log replies when they arrive. - New *Before READY* checklist for CVE records: remove calculator-default or unassessed metrics, don't leave the default status as `unaffected` unless assessed, check the metadata used in generated emails, and compare saves by content because editors reorder JSON keys. - New *Publication sequence*: READY → send the advisory emails from the portal and confirm each in the list archives → add the `vendor-advisory` reference → ASF Security sets PUBLIC. - New disclosure-notice template for reporters, and sending guidance: send ASF list mail from an `@apache.org` address, and check drafts made by automation for rewritten links. - Pre-disclosure public text (announcements, blog posts, website) stays neutral, and the instructions given to whoever writes it must not reveal what is being withheld. **roller-release** - Tally binding votes against the ASF roster rather than the website committer list. - Send announcements from an `@apache.org` address and confirm them in the announce@ archive. - Promote a candidate with one `svn mv` commit from a sparse checkout of the repository root; follow redirects when verifying public download URLs, since downloads.apache.org redirects missing files to the archive. - Rebase website changes onto the publishing branch, preview with `content/` as the web root, and check the rendered HTML (Markdown tables may not be enabled). Checked with `skills/roller-security/scripts/check-private.sh --range origin/master..HEAD` (clean). The item template still parses with `triage-status.py`. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
