dev
Thread
Date
Earlier messages
Later messages
Messages by Date
2026/04/14
[PR] #1158 - move error handling to database (tooling-trusted-releases)
via GitHub
2026/04/14
[PR] Adding endpoint to list projects using CI staging (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] Make build-bootstrap error (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] Make build-bootstrap error (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] Investigate remote promotion of artifacts on third party platforms (tooling-trusted-releases)
via GitHub
2026/04/13
[PR] Adding mermaid back in (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] SSH Authentication Surface Not Covered in Authentication Security Documentation (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] Internal Documentation Publicly Exposed (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] Archive Extraction Does Not Inspect or Sanitize SVG Files (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] Internal Documentation Publicly Exposed (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] Archive Extraction Does Not Inspect or Sanitize SVG Files (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] No SVG Sanitization Library or Function Exists in Codebase (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] JWT API Authentication Success Not Logged (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] JWT API Authentication Success Not Logged (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] SSH Authentication Surface Not Covered in Authentication Security Documentation (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] No SVG Sanitization Library or Function Exists in Codebase (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] Form Validation Error Messages Rendered as Unescaped HTML (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] Form Validation Error Messages Rendered as Unescaped HTML (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] OAuth Authentication Does Not Terminate Prior Session Token (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] OAuth Authentication Does Not Terminate Prior Session Token (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] Dynamic Field Assignment Without Explicit Allowlist in Policy Updates (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] Resource-Committee Validation Control Not Applied Across Storage Writers (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] Dynamic Field Assignment Without Explicit Allowlist in Policy Updates (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] IDOR on check_id in Check Result Data Endpoint (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] Missing Project-Level Access Control on Multiple GET Endpoints (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] Resource-Committee Validation Control Not Applied Across Storage Writers (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] Public API Endpoints Expose Internal Implementation Fields (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] Public API Endpoints Expose Internal Implementation Fields (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] IDOR on check_id in Check Result Data Endpoint (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] Missing Project-Level Access Control on Multiple GET Endpoints (tooling-trusted-releases)
via GitHub
2026/04/13
[PR] Adding ssh specifics to docs (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] HTTP Redirects Followed Without Target Domain Validation (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] Add SWHID identifiers for release verification (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] Document when second round podling votes can be held on `general@` (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] Document when second round podling votes can be held on `general@` (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [PR] Invalidate SSH keys (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] Add SWHID identifiers for release verification (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] Document when second round podling votes can be held on `general@` (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] Vote Resolution Phase Transitions Lack Optimistic Locking (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] Vote Resolution Phase Transitions Lack Optimistic Locking (tooling-trusted-releases)
via GitHub
2026/04/13
[I] Add a podling disclaimer to podling release announcements (tooling-trusted-releases)
via GitHub
2026/04/13
[I] Fix bugs in the vote page for second round podling votes (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] Document when second round podling votes can be held on `general@` (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] Document when second round podling votes can be held on `general@` (tooling-trusted-releases)
via GitHub
2026/04/13
[I] Votes cast on ATR by IPMC members may fail in the second podling round (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] Document when second round podling votes can be held on `general@` (tooling-trusted-releases)
via GitHub
2026/04/13
[I] Do not allow first round podling votes to be sent to private lists (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] Send form validation errors through the database, not through flash cookies (tooling-trusted-releases)
via GitHub
2026/04/13
[I] Send form validation errors through the database, not through flash cookies (tooling-trusted-releases)
via GitHub
2026/04/13
[I] Hard link files in the incubator directory for podling releases (tooling-trusted-releases)
via GitHub
2026/04/13
[I] Tabulate votes from the IPMC in the second podling vote round only (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] Add SWHID identifiers for release verification (tooling-trusted-releases)
via GitHub
2026/04/13
[I] Document when second round podling votes can be held on `general@` (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] Add SWHID identifiers for release verification (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] Thread ID Parameter Lacks Format Validation Before Server-Side Request (tooling-trusted-releases)
via GitHub
2026/04/13
Re: [I] API Models Lack Cross-Field Contextual Validation (tooling-trusted-releases)
via GitHub
2026/04/12
Re: [I] Add SWHID identifiers for release verification (tooling-trusted-releases)
via GitHub
2026/04/11
Re: [I] API Models Lack Cross-Field Contextual Validation (tooling-trusted-releases)
via GitHub
2026/04/11
Re: [I] Add SWHID identifiers for release verification (tooling-trusted-releases)
via GitHub
2026/04/11
Re: [I] Add SWHID identifiers for release verification (tooling-trusted-releases)
via GitHub
2026/04/11
Re: [I] Add SWHID identifiers for release verification (tooling-trusted-releases)
via GitHub
2026/04/11
[I] Add SWHID identifiers for release verification (tooling-trusted-releases)
via GitHub
2026/04/11
Re: [I] Full Email Content Logged at INFO Level (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [PR] Invalidate SSH keys (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] Vote Tabulation Authorization Check Commented Out (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] ldap.is_active() Returns True When LDAP Is Unconfigured (Fail-Open) (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] ldap.is_active() Returns True When LDAP Is Unconfigured (Fail-Open) (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] Unbounded Directory Traversal and File Hashing in Signature Provenance Endpoint (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] Unbounded Directory Traversal and File Hashing in Signature Provenance Endpoint (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] No Session Termination After SSH Key Changes (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] No Session Termination After SSH Key Changes (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] MFA OAuth logins fail for developers without LDAP credentials (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] MFA OAuth logins fail for developers without LDAP credentials (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [PR] Invalidate SSH keys (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] MFA OAuth logins fail for developers without LDAP credentials (tooling-trusted-releases)
via GitHub
2026/04/10
[I] MFA OAuth logins fail for developers without LDAP credentials (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] No Session Termination After SSH Key Changes (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] Web-Issued JWTs Cannot Be Revoked and Survive PAT Deletion (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] Web-Issued JWTs Cannot Be Revoked and Survive PAT Deletion (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] Remove the ability to generate test JWT tokens (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] ATR JWTs Lack Explicit Token Type Identification (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] Full Email Content Logged at INFO Level (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] rsync Subprocess Execution Without Timeout (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] rsync Subprocess Execution Without Timeout (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] Distribution Operations Have No Audit Logging (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] API JWT Creation Endpoint Missing Cache-Control Header (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] API JWT Creation Endpoint Missing Cache-Control Header (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] Admin Token Revocation Does Not Terminate User Web Sessions (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] Admin Token Revocation Does Not Terminate User Web Sessions (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] Admin Token Revocation Does Not Terminate User Web Sessions (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] SSH server lacks brute force protection (tooling-trusted-releases)
via GitHub
2026/04/10
[GH] Invalidate SSH keys (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] SSH Host Key Generated with RSA 2048-bit (~112 bits of security) (tooling-trusted-releases)
via GitHub
2026/04/10
[I] Remove the ability to generate test JWT tokens (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] Remove the ability to generate test JWT tokens (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] No Session Termination After PAT Deletion or Creation (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] No Session Termination After PAT Deletion or Creation (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] No Session Termination After PAT Deletion or Creation (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] No Automatic Credential Revocation on Account Disable (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] TLS: Add explicit cipher suite configuration for defense-in-depth (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] No Session Termination After PAT Deletion or Creation (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] In-Memory Hash Function Could Process Unbounded Data (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] In-Memory Hash Function Could Process Unbounded Data (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] Setup svn credentials to commit to dist/release (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] TLS: Add explicit cipher suite configuration for defense-in-depth (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] SSH Interface Lacks Rate Limiting for Write Operations (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [PR] #1003 - add rate limiting to SSH connections (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] Git Clone Operations Without Network Timeout (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] Implement server-side session store to enable session revocation (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [PR] Store session data in the server (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] Implement server-side session store to enable session revocation (tooling-trusted-releases)
via GitHub
2026/04/10
Re: [I] Setup svn credentials to commit to dist/release (tooling-trusted-releases)
via GitHub
2026/04/10
[GH] Store session data in the server (tooling-trusted-releases)
via GitHub
2026/04/10
[GH] Store session data in the server (tooling-trusted-releases)
via GitHub
2026/04/10
[GH] Store session data in the server (tooling-trusted-releases)
via GitHub
2026/04/10
[GH] Store session data in the server (tooling-trusted-releases)
via GitHub
2026/04/10
[GH] Store session data in the server (tooling-trusted-releases)
via GitHub
2026/04/09
Re: [I] Full Email Content Logged at INFO Level (tooling-trusted-releases)
via GitHub
2026/04/09
[PR] Store session data in the server (tooling-trusted-releases)
via GitHub
2026/04/09
[I] API to list PMCs approved for CI staging (tooling-trusted-releases)
via GitHub
2026/04/09
[GH] #1003 - add rate limiting to SSH connections (tooling-trusted-releases)
via GitHub
2026/04/09
Re: [I] JWT TTL Documentation Discrepancy (30 Minutes Actual vs 90 Minutes Documented) (tooling-trusted-releases)
via GitHub
2026/04/09
Re: [I] JWT TTL Documentation Discrepancy (30 Minutes Actual vs 90 Minutes Documented) (tooling-trusted-releases)
via GitHub
2026/04/09
Re: [I] JWT TTL Documentation Discrepancy (30 Minutes Actual vs 90 Minutes Documented) (tooling-trusted-releases)
via GitHub
2026/04/09
Re: [I] Swagger UI and OpenAPI Specification Publicly Accessible (tooling-trusted-releases)
via GitHub
2026/04/09
Re: [I] Discuss how we handle private mailing list votes in the security model (tooling-trusted-releases)
via GitHub
2026/04/09
Re: [I] Full Email Content Logged at INFO Level (tooling-trusted-releases)
via GitHub
2026/04/09
Re: [I] Vote Policy Form Bypasses Minimum Hours Range Check (tooling-trusted-releases)
via GitHub
2026/04/09
Re: [I] Vote Duration Not Validated Against Release Policy Minimum (tooling-trusted-releases)
via GitHub
2026/04/09
Re: [I] Vote Duration Not Validated Against Release Policy Minimum (tooling-trusted-releases)
via GitHub
2026/04/09
Re: [I] Unsandboxed render_string_sync API Allows Arbitrary Jinja2 Template Compilation (tooling-trusted-releases)
via GitHub
2026/04/09
Re: [I] Vote Policy Form Bypasses Minimum Hours Range Check (tooling-trusted-releases)
via GitHub
2026/04/09
Re: [I] Vote Policy Form Bypasses Minimum Hours Range Check (tooling-trusted-releases)
via GitHub
2026/04/09
Re: [I] Debug print() Bypasses Structured Logging (tooling-trusted-releases)
via GitHub
2026/04/09
Re: [PR] Use the debug print format that is used throughout osv.py (tooling-trusted-releases)
via GitHub
2026/04/09
[I] Add logging framework to SBOM CLI (tooling-trusted-releases)
via GitHub
2026/04/09
Re: [PR] Use the debug print format that is used throughout osv.py (tooling-trusted-releases)
via GitHub
2026/04/09
Re: [I] Debug print() Bypasses Structured Logging (tooling-trusted-releases)
via GitHub
2026/04/09
Re: [PR] Use the debug print format that is used throughout osv.py (tooling-trusted-releases)
via GitHub
2026/04/09
Re: [I] Unbounded Directory Traversal and File Hashing in Signature Provenance Endpoint (tooling-trusted-releases)
via GitHub
2026/04/09
Re: [I] Git Clone Operations Without Network Timeout (tooling-trusted-releases)
via GitHub
2026/04/09
Re: [PR] Use the debug print format that is used throughout osv.py (tooling-trusted-releases)
via GitHub
2026/04/09
[PR] Use the debug print format that is used throughout osv.pysv (tooling-trusted-releases)
via GitHub
2026/04/09
Re: [I] Unsandboxed render_string_sync API Allows Arbitrary Jinja2 Template Compilation (tooling-trusted-releases)
via GitHub
2026/04/09
Re: [I] Unsandboxed render_string_sync API Allows Arbitrary Jinja2 Template Compilation (tooling-trusted-releases)
via GitHub
2026/04/09
Re: [I] No Validation of Uploaded OpenPGP Key Cryptographic Strength (tooling-trusted-releases)
via GitHub
2026/04/09
Re: [I] Archive Extraction Size Tracking Reset by Metadata Files (tooling-trusted-releases)
via GitHub
2026/04/09
Re: [I] Git Clone Operations Without Network Timeout (tooling-trusted-releases)
via GitHub
2026/04/09
Re: [I] Git Clone Operations Without Network Timeout (tooling-trusted-releases)
via GitHub
2026/04/09
Re: [I] Git Clone Operations Without Network Timeout (tooling-trusted-releases)
via GitHub
2026/04/09
[PR] #1003 - add rate limiting to SSH connections (tooling-trusted-releases)
via GitHub
2026/04/09
Re: [I] Git Clone Operations Without Network Timeout (tooling-trusted-releases)
via GitHub
2026/04/09
Re: [I] Thread Message Fetching Without Timeout or Concurrency Limit (tooling-trusted-releases)
via GitHub
2026/04/09
Re: [I] OSV Vulnerability Scanning Has No HTTP Timeout (tooling-trusted-releases)
via GitHub
2026/04/09
Re: [I] IDOR in Check Ignore Operations via Numeric ID (tooling-trusted-releases)
via GitHub
2026/04/09
Re: [I] IDOR in Check Ignore Operations via Numeric ID (tooling-trusted-releases)
via GitHub
2026/04/09
Re: [PR] Bump cryptography from 46.0.6 to 46.0.7 (tooling-trusted-releases)
via GitHub
2026/04/09
Re: [PR] Bump cryptography from 46.0.6 to 46.0.7 (tooling-trusted-releases)
via GitHub
2026/04/09
Re: [PR] Bump cryptography from 46.0.6 to 46.0.7 (tooling-trusted-releases)
via GitHub
2026/04/09
[GH] Invalidate SSH keys (tooling-trusted-releases)
via GitHub
2026/04/08
Re: [I] Unbounded Distribution Status Check Loop (tooling-trusted-releases)
via GitHub
2026/04/08
Re: [I] Preserve the history of configuration options that affect attestations (tooling-trusted-releases)
via GitHub
2026/04/08
Re: [I] Consider moving the PubSub code to ASFQuart (tooling-trusted-releases)
via GitHub
2026/04/08
Re: [PR] Auth audit log and user preferences (tooling-trusted-releases)
via GitHub
2026/04/08
Re: [I] Web-Based JWT Issuance Not Audit-Logged (tooling-trusted-releases)
via GitHub
2026/04/08
Re: [I] Document database cascades (tooling-trusted-releases)
via GitHub
2026/04/08
Re: [I] Projects VM track (tooling-trusted-releases)
via GitHub
2026/04/08
Re: [I] Document vhost configuration (tooling-trusted-releases)
via GitHub
2026/04/08
Re: [I] PAT Validation Exceptions Return HTTP 500 Instead of 401 (tooling-trusted-releases)
via GitHub
2026/04/08
Re: [I] No SVG Sanitization Library or Function Exists in Codebase (tooling-trusted-releases)
via GitHub
2026/04/08
Re: [I] Resolve security issues with Mermaid dependencies (tooling-trusted-releases)
via GitHub
2026/04/08
Re: [I] Admin User Impersonation Has No Audit Trail (tooling-trusted-releases)
via GitHub
2026/04/08
Re: [I] No Validation of Uploaded OpenPGP Key Cryptographic Strength (tooling-trusted-releases)
via GitHub
2026/04/08
[PR] Bump cryptography from 46.0.6 to 46.0.7 (tooling-trusted-releases)
via GitHub
2026/04/08
Re: [I] Make the user interface clearer in the finish phase (tooling-trusted-releases)
via GitHub
2026/04/08
Re: [I] Document vhost configuration (tooling-trusted-releases)
via GitHub
2026/04/08
Re: [I] Research whether structured ASFQuart permissions can be used more widely in ATR (tooling-trusted-releases)
via GitHub
2026/04/08
Re: [I] Discuss upstreaming of certain components (tooling-trusted-releases)
via GitHub
2026/04/08
Re: [I] Archive Extraction Does Not Inspect or Sanitize SVG Files (tooling-trusted-releases)
via GitHub
2026/04/08
Re: [I] Projects VM track (tooling-trusted-releases)
via GitHub
2026/04/08
Re: [PR] Adding docs for cascading (tooling-trusted-releases)
via GitHub
2026/04/08
Re: [I] Preserve the history of configuration options that affect attestations (tooling-trusted-releases)
via GitHub
2026/04/08
Re: [I] Allow error check results to be turned into a TODO list (tooling-trusted-releases)
via GitHub
2026/04/08
Re: [I] Study replacing repository.apache.org (tooling-trusted-releases)
via GitHub
2026/04/08
Re: [I] API Models Accept Client-Submitted Identity Alongside JWT (tooling-trusted-releases)
via GitHub
2026/04/08
Re: [I] SSH Authentication Success Not Logged (tooling-trusted-releases)
via GitHub
2026/04/08
Re: [I] Resolve security issues with Mermaid dependencies (tooling-trusted-releases)
via GitHub
2026/04/08
[I] Resolve security issues with Mermaid (tooling-trusted-releases)
via GitHub
2026/04/08
Re: [PR] Fix build-bootstrap by resolving ICU dependency for dart-sass (tooling-trusted-releases)
via GitHub
2026/04/08
Re: [PR] Fix build-bootstrap by resolving ICU dependency for dart-sass (tooling-trusted-releases)
via GitHub
2026/04/08
[PR] Auth audit log and user preferences (tooling-trusted-releases)
via GitHub
2026/04/07
Re: [I] No Evidence of postMessage Origin Validation in Application (tooling-trusted-releases)
via GitHub
2026/04/07
Re: [I] No Evidence of postMessage Origin Validation in Application (tooling-trusted-releases)
via GitHub
2026/04/07
Re: [I] Unverifiable Session Cookie Write in atr.util (tooling-trusted-releases)
via GitHub
2026/04/07
Re: [I] Unverifiable Session Cookie Write in atr.util (tooling-trusted-releases)
via GitHub
2026/04/07
Re: [I] Client-Side JWT Display TypeScript Not Available for Complete Audit (tooling-trusted-releases)
via GitHub
2026/04/07
Re: [I] Client-Side JWT Display TypeScript Not Available for Complete Audit (tooling-trusted-releases)
via GitHub
2026/04/07
[PR] Fix build-bootstrap by resolving ICU dependency for dart-sass (tooling-trusted-releases)
via GitHub
2026/04/07
Re: [PR] Invalidate SSH keys (tooling-trusted-releases)
via GitHub
2026/04/07
Re: [I] pre-commit: add `markdown-link-check` to check for dead links in Markdown files (tooling-docs)
via GitHub
Earlier messages
Later messages