dev
Thread
Date
Earlier messages
Later messages
Messages by Thread
Re: [PR] Refactor Dockerfile to streamline Apache RAT installation (tooling-trusted-releases)
via GitHub
Re: [I] Allow release managers to be designated (tooling-trusted-releases)
via GitHub
Re: [I] Allow release managers to be designated (tooling-trusted-releases)
via GitHub
[I] Make the user interface clearer in the finish phase (tooling-trusted-releases)
via GitHub
Re: [I] Make the user interface clearer in the finish phase (tooling-trusted-releases)
via GitHub
Re: [I] Make the user interface clearer in the finish phase (tooling-trusted-releases)
via GitHub
Re: [I] Make the user interface clearer in the finish phase (tooling-trusted-releases)
via GitHub
Re: [I] Make the user interface clearer in the finish phase (tooling-trusted-releases)
via GitHub
Re: [I] Make the user interface clearer in the finish phase (tooling-trusted-releases)
via GitHub
Re: [I] Make the user interface clearer in the finish phase (tooling-trusted-releases)
via GitHub
Re: [I] Make the user interface clearer in the finish phase (tooling-trusted-releases)
via GitHub
[I] Fix Litestream backups (tooling-trusted-releases)
via GitHub
Re: [I] Fix Litestream backups (tooling-trusted-releases)
via GitHub
Re: [I] Fix Litestream backups (tooling-trusted-releases)
via GitHub
[I] Investigate remote promotion of artifacts on third party platforms (tooling-trusted-releases)
via GitHub
Re: [I] Investigate remote promotion of artifacts on third party platforms (tooling-trusted-releases)
via GitHub
Re: [I] Investigate remote promotion of artifacts on third party platforms (tooling-trusted-releases)
via GitHub
Re: [I] Investigate remote promotion of artifacts on third party platforms (tooling-trusted-releases)
via GitHub
Re: [I] Investigate remote promotion of artifacts on third party platforms (tooling-trusted-releases)
via GitHub
Re: [I] Investigate remote promotion of artifacts on third party platforms (tooling-trusted-releases)
via GitHub
Re: [I] Investigate remote promotion of artifacts on third party platforms (tooling-trusted-releases)
via GitHub
Re: [I] Investigate remote promotion of artifacts on third party platforms (tooling-trusted-releases)
via GitHub
Re: [I] Investigate remote promotion of artifacts on third party platforms (tooling-trusted-releases)
via GitHub
Re: [I] Investigate remote promotion of artifacts on third party platforms (tooling-trusted-releases)
via GitHub
Re: [I] Investigate remote promotion of artifacts on third party platforms (tooling-trusted-releases)
via GitHub
Re: [I] Investigate remote promotion of artifacts on third party platforms (tooling-trusted-releases)
via GitHub
Re: [I] Investigate remote promotion of artifacts on third party platforms (tooling-trusted-releases)
via GitHub
Re: [I] Investigate remote promotion of artifacts on third party platforms (tooling-trusted-releases)
via GitHub
[PR] Improve curl download scripting (tooling-trusted-releases)
via GitHub
Re: [PR] Improve curl download scripting (tooling-trusted-releases)
via GitHub
Re: [I] Invalidate all PATs when user account is disabled (tooling-trusted-releases)
via GitHub
Re: [I] Enforce absolute maximum session lifetime for web sessions (tooling-trusted-releases)
via GitHub
Re: [I] Enforce absolute maximum session lifetime for web sessions (tooling-trusted-releases)
via GitHub
Re: [I] Enforce absolute maximum session lifetime for web sessions (tooling-trusted-releases)
via GitHub
Re: [I] Improve error reporting when /resolve/tabulated data is unavailable (tooling-trusted-releases)
via GitHub
Re: [I] Improve error reporting when /resolve/tabulated data is unavailable (tooling-trusted-releases)
via GitHub
Re: [I] Improve error reporting when /resolve/tabulated data is unavailable (tooling-trusted-releases)
via GitHub
Re: [I] Improve error reporting when /resolve/tabulated data is unavailable (tooling-trusted-releases)
via GitHub
Re: [I] Improve error reporting when /resolve/tabulated data is unavailable (tooling-trusted-releases)
via GitHub
Re: [I] Improve error reporting when /resolve/tabulated data is unavailable (tooling-trusted-releases)
via GitHub
Re: [I] /api/project/releases/{name} should return 404 for non-existent project (tooling-trusted-releases)
via GitHub
Re: [I] Improve the accuracy and UI for the OSV vulnerability scanner (tooling-trusted-releases)
via GitHub
Re: [I] Improve the accuracy and UI for the OSV vulnerability scanner (tooling-trusted-releases)
via GitHub
Re: [I] Improve the accuracy and UI for the OSV vulnerability scanner (tooling-trusted-releases)
via GitHub
Re: [I] Require two approvals for important actions (tooling-trusted-releases)
via GitHub
Re: [I] Require two approvals for important actions (tooling-trusted-releases)
via GitHub
Re: [I] Require two approvals for important actions (tooling-trusted-releases)
via GitHub
Re: [I] Require two approvals for important actions (tooling-trusted-releases)
via GitHub
Re: [I] Require two approvals for important actions (tooling-trusted-releases)
via GitHub
[PR] Bump werkzeug from 3.1.5 to 3.1.6 (tooling-trusted-releases)
via GitHub
Re: [PR] Bump werkzeug from 3.1.5 to 3.1.6 (tooling-trusted-releases)
via GitHub
Re: [PR] Bump werkzeug from 3.1.5 to 3.1.6 (tooling-trusted-releases)
via GitHub
[PR] Bump flask from 3.1.2 to 3.1.3 (tooling-trusted-releases)
via GitHub
Re: [PR] Bump flask from 3.1.2 to 3.1.3 (tooling-trusted-releases)
via GitHub
Re: [PR] Bump flask from 3.1.2 to 3.1.3 (tooling-trusted-releases)
via GitHub
[I] Fix the form to move files in the finish phase, and add regression tests (tooling-trusted-releases)
via GitHub
Re: [I] Fix the form to move files in the finish phase, and add regression tests (tooling-trusted-releases)
via GitHub
Re: [I] Fix the form to move files in the finish phase, and add regression tests (tooling-trusted-releases)
via GitHub
[PR] Updated implementation of check hash checks for caching (tooling-trusted-releases)
via GitHub
[GH] Updated implementation of check hash checks for caching (tooling-trusted-releases)
via GitHub
[GH] Updated implementation of check hash checks for caching (tooling-trusted-releases)
via GitHub
[GH] Updated implementation of check hash checks for caching (tooling-trusted-releases)
via GitHub
Re: [PR] Updated implementation of check hash checks for caching (tooling-trusted-releases)
via GitHub
Re: [PR] Updated implementation of check hash checks for caching (tooling-trusted-releases)
via GitHub
[PR] Introduce ATR_STATUS and control recipient lists (tooling-trusted-releases)
via GitHub
Re: [PR] Introduce ATR_STATUS and control recipient lists (tooling-trusted-releases)
via GitHub
Re: [I] Ensure that a project can only be deleted or archived under certain conditions, and that the state is clear (tooling-trusted-releases)
via GitHub
Re: [I] Ensure that a project can only be deleted or archived under certain conditions, and that the state is clear (tooling-trusted-releases)
via GitHub
Re: [I] Ensure that a project can only be deleted or archived under certain conditions, and that the state is clear (tooling-trusted-releases)
via GitHub
Re: [I] Ensure that a project can only be deleted or archived under certain conditions, and that the state is clear (tooling-trusted-releases)
via GitHub
Re: [I] Ensure that a project can only be deleted or archived under certain conditions, and that the state is clear (tooling-trusted-releases)
via GitHub
[PR] Return 404 when project is unknown in api endpoint call (tooling-trusted-releases)
via GitHub
Re: [PR] Return 404 when project is unknown in api endpoint call (tooling-trusted-releases)
via GitHub
[PR] Invalidate pats manually 598 (tooling-trusted-releases)
via GitHub
Re: [PR] Invalidate pats manually 598 (tooling-trusted-releases)
via GitHub
Re: [I] Escape database values before writing to database (tooling-trusted-releases)
via GitHub
Re: [I] Escape database values before writing to database (tooling-trusted-releases)
via GitHub
[PR] Block SCM directories (tooling-trusted-releases)
via GitHub
Re: [PR] Block SCM directories (tooling-trusted-releases)
via GitHub
[PR] Redact sensitive configurations (tooling-trusted-releases)
via GitHub
Re: [PR] Redact sensitive configurations (tooling-trusted-releases)
via GitHub
[PR] Assure debug mode is only set in development (tooling-trusted-releases)
via GitHub
Re: [PR] Assure debug mode is only set in development (tooling-trusted-releases)
via GitHub
[I] Bug: RAO / maven upload only works for single release artifact (+classifiers) (tooling-trusted-releases)
via GitHub
Re: [I] Bug: RAO / maven upload only works for single release artifact (+classifiers) (tooling-trusted-releases)
via GitHub
Re: [I] Bug: RAO / maven upload only works for single release artifact (+classifiers) (tooling-trusted-releases)
via GitHub
Re: [I] Bug: RAO / maven upload only works for single release artifact (+classifiers) (tooling-trusted-releases)
via GitHub
Re: [I] RAO / maven upload only works for single release artifact (+classifiers) (tooling-trusted-releases)
via GitHub
Re: [I] RAO / maven upload only works for single release artifact (+classifiers) (tooling-trusted-releases)
via GitHub
Re: [I] RAO / maven upload only works for single release artifact (+classifiers) (tooling-trusted-releases)
via GitHub
Re: [I] RAO / maven upload only works for single release artifact (+classifiers) (tooling-trusted-releases)
via GitHub
Re: [I] RAO / maven upload only works for single release artifact (+classifiers) (tooling-trusted-releases)
via GitHub
Re: [I] RAO / maven upload only works for single release artifact (+classifiers) (tooling-trusted-releases)
via GitHub
[I] Handle session isolation for mixed authentication methods (tooling-trusted-releases)
via GitHub
Re: [I] Handle session isolation for mixed authentication methods (tooling-trusted-releases)
via GitHub
Re: [I] Handle session isolation for mixed authentication methods (tooling-trusted-releases)
via GitHub
Re: [I] Handle session isolation for mixed authentication methods (tooling-trusted-releases)
via GitHub
Re: [I] Handle session isolation for mixed authentication methods (tooling-trusted-releases)
via GitHub
[I] Invalidate all SSH keys when user account is disabled (tooling-trusted-releases)
via GitHub
Re: [I] Invalidate all SSH keys when user account is disabled (tooling-trusted-releases)
via GitHub
Re: [I] Invalidate all SSH keys when user account is disabled (tooling-trusted-releases)
via GitHub
[I] Invalidate authorization cache and session file cache on logout/session termination (tooling-trusted-releases)
via GitHub
Re: [I] Invalidate authorization cache and session file cache on logout/session termination (tooling-trusted-releases)
via GitHub
Re: [I] Invalidate authorization cache and session file cache on logout/session termination (tooling-trusted-releases)
via GitHub
Re: [I] Invalidate authorization cache and session file cache on logout/session termination (tooling-trusted-releases)
via GitHub
Re: [I] Invalidate authorization cache and session file cache on logout/session termination (tooling-trusted-releases)
via GitHub
Re: [I] Invalidate authorization cache and session file cache on logout/session termination (tooling-trusted-releases)
via GitHub
Re: [I] Invalidate authorization cache and session file cache on logout/session termination (tooling-trusted-releases)
via GitHub
[I] Add LDAP account status check to session and JWT validation (tooling-trusted-releases)
via GitHub
Re: [I] Add LDAP account status check to session and JWT validation (tooling-trusted-releases)
via GitHub
Re: [I] Add LDAP account status check to session and JWT validation (tooling-trusted-releases)
via GitHub
Re: [I] Add LDAP account status check to session and JWT validation (tooling-trusted-releases)
via GitHub
[I] Document safe usage of `cmarkgfm` (tooling-trusted-releases)
via GitHub
Re: [I] Document safe usage of `cmarkgfm` (tooling-trusted-releases)
via GitHub
Re: [I] Document safe usage of `cmarkgfm` (tooling-trusted-releases)
via GitHub
[I] Add session regeneration on OAuth authentication (tooling-trusted-releases)
via GitHub
[I] Implement JWT token revocation mechanism (tooling-trusted-releases)
via GitHub
Re: [I] Implement JWT token revocation mechanism (tooling-trusted-releases)
via GitHub
Re: [I] Implement JWT token revocation mechanism (tooling-trusted-releases)
via GitHub
[I] Implement server-side session store to enable session revocation (tooling-trusted-releases)
via GitHub
Re: [I] Implement server-side session store to enable session revocation (tooling-trusted-releases)
via GitHub
Re: [I] Implement server-side session store to enable session revocation (tooling-trusted-releases)
via GitHub
Re: [I] Implement server-side session store to enable session revocation (tooling-trusted-releases)
via GitHub
Re: [I] Implement server-side session store to enable session revocation (tooling-trusted-releases)
via GitHub
Re: [I] Implement server-side session store to enable session revocation (tooling-trusted-releases)
via GitHub
Re: [I] Implement server-side session store to enable session revocation (tooling-trusted-releases)
via GitHub
Re: [I] Implement server-side session store to enable session revocation (tooling-trusted-releases)
via GitHub
[I] Create security documentation for authentication defense controls (tooling-trusted-releases)
via GitHub
Re: [I] Create security documentation for authentication defense controls (tooling-trusted-releases)
via GitHub
Re: [I] Create security documentation for authentication defense controls (tooling-trusted-releases)
via GitHub
[I] Work on using config option for alpha-only (tooling-trusted-releases)
via GitHub
Re: [I] Work on using config option for alpha-only (tooling-trusted-releases)
via GitHub
[I] Make test email address conditional on test environment (tooling-trusted-releases)
via GitHub
Re: [I] Make test email address conditional on test environment (tooling-trusted-releases)
via GitHub
Re: [I] Make test email address conditional on test environment (tooling-trusted-releases)
via GitHub
[I] Move hardcoded committee membership to external configuration (tooling-trusted-releases)
via GitHub
Re: [I] Move hardcoded committee membership to external configuration (tooling-trusted-releases)
via GitHub
Re: [I] Move hardcoded committee membership to external configuration (tooling-trusted-releases)
via GitHub
[I] Add production safety check for ALLOW_TESTS configuration (tooling-trusted-releases)
via GitHub
Re: [I] Add production safety check for ALLOW_TESTS configuration (tooling-trusted-releases)
via GitHub
[I] Implement authentication failure logging (tooling-trusted-releases)
via GitHub
Re: [I] Implement authentication failure logging (tooling-trusted-releases)
via GitHub
[I] Add rate limiting to Trusted Publisher JWT API endpoints (tooling-trusted-releases)
via GitHub
Re: [I] Add rate limiting to Trusted Publisher JWT API endpoints (tooling-trusted-releases)
via GitHub
Re: [I] Add rate limiting to Trusted Publisher JWT API endpoints (tooling-trusted-releases)
via GitHub
[I] SSH server lacks brute force protection (tooling-trusted-releases)
via GitHub
Re: [I] SSH server lacks brute force protection (tooling-trusted-releases)
via GitHub
Re: [I] SSH server lacks brute force protection (tooling-trusted-releases)
via GitHub
[I] Insufficient archive member path validation in check tasks (tooling-trusted-releases)
via GitHub
Re: [I] Insufficient archive member path validation in check tasks (tooling-trusted-releases)
via GitHub
Re: [I] Insufficient archive member path validation in check tasks (tooling-trusted-releases)
via GitHub
Re: [I] Insufficient archive member path validation in check tasks (tooling-trusted-releases)
via GitHub
[I] Apply `form.to_relpath()` consistently in `draft.py` and `finish.py` POST handlers (tooling-trusted-releases)
via GitHub
Re: [I] Apply `form.to_relpath()` consistently in `draft.py` and `finish.py` POST handlers (tooling-trusted-releases)
via GitHub
Re: [I] Apply `form.to_relpath()` consistently in `draft.py` and `finish.py` POST handlers (tooling-trusted-releases)
via GitHub
[I] Path traversal in storage layer `delete_file` and `generate_hash_file` (tooling-trusted-releases)
via GitHub
Re: [I] Path traversal in storage layer `delete_file` and `generate_hash_file` (tooling-trusted-releases)
via GitHub
Re: [I] Path traversal in storage layer `delete_file` and `generate_hash_file` (tooling-trusted-releases)
via GitHub
Re: [I] Path traversal in storage layer `delete_file` and `generate_hash_file` (tooling-trusted-releases)
via GitHub
Re: [I] Path traversal in storage layer `delete_file` and `generate_hash_file` (tooling-trusted-releases)
via GitHub
Re: [I] Path traversal in storage layer `delete_file` and `generate_hash_file` (tooling-trusted-releases)
via GitHub
[I] Path traversal in attestable file path construction (tooling-trusted-releases)
via GitHub
Re: [I] Path traversal in attestable file path construction (tooling-trusted-releases)
via GitHub
Re: [I] Path traversal in attestable file path construction (tooling-trusted-releases)
via GitHub
Re: [I] Path traversal in attestable file path construction (tooling-trusted-releases)
via GitHub
Re: [I] Path traversal in attestable file path construction (tooling-trusted-releases)
via GitHub
Re: [I] Path traversal in attestable file path construction (tooling-trusted-releases)
via GitHub
[I] Add content size limits to SVN import (tooling-trusted-releases)
via GitHub
Re: [I] Add content size limits to SVN import (tooling-trusted-releases)
via GitHub
Re: [I] Add content size limits to SVN import (tooling-trusted-releases)
via GitHub
Re: [I] Add content size limits to SVN import (tooling-trusted-releases)
via GitHub
Re: [I] Add content size limits to SVN import (tooling-trusted-releases)
via GitHub
Re: [I] Add content size limits to SVN import (tooling-trusted-releases)
via GitHub
Re: [I] Add content size limits to SVN import (tooling-trusted-releases)
via GitHub
Re: [I] Add content size limits to SVN import (tooling-trusted-releases)
via GitHub
Re: [I] Add content size limits to SVN import (tooling-trusted-releases)
via GitHub
Re: [I] Add content size limits to SVN import (tooling-trusted-releases)
via GitHub
Re: [I] Add content size limits to SVN import (tooling-trusted-releases)
via GitHub
Re: [I] Add content size limits to SVN import (tooling-trusted-releases)
via GitHub
Re: [I] Add content size limits to SVN import (tooling-trusted-releases)
via GitHub
Re: [I] Add content size limits to SVN import (tooling-trusted-releases)
via GitHub
Re: [I] Add content size limits to SVN import (tooling-trusted-releases)
via GitHub
Re: [I] Add content size limits to SVN import (tooling-trusted-releases)
via GitHub
[I] Add size limits to LICENSE/NOTICE file reads and remote KEYS fetch (tooling-trusted-releases)
via GitHub
Re: [I] Add size limits to LICENSE/NOTICE file reads and remote KEYS fetch (tooling-trusted-releases)
via GitHub
Re: [I] Add size limits to LICENSE/NOTICE file reads and remote KEYS fetch (tooling-trusted-releases)
via GitHub
[I] Add size limits to SSH/rsync file uploads (tooling-trusted-releases)
via GitHub
Re: [I] Add size limits to SSH/rsync file uploads (tooling-trusted-releases)
via GitHub
Re: [I] Add size limits to SSH/rsync file uploads (tooling-trusted-releases)
via GitHub
Re: [I] Add size limits to SSH/rsync file uploads (tooling-trusted-releases)
via GitHub
Re: [I] Add size limits to SSH/rsync file uploads (tooling-trusted-releases)
via GitHub
Re: [I] Add size limits to SSH/rsync file uploads (tooling-trusted-releases)
via GitHub
Re: [I] Add size limits to SSH/rsync file uploads (tooling-trusted-releases)
via GitHub
Re: [I] Add size limits to SSH/rsync file uploads (tooling-trusted-releases)
via GitHub
[I] Enforce MAX_CONTENT_LENGTH and add file upload size limits across all HTTP entry points (tooling-trusted-releases)
via GitHub
Re: [I] Enforce MAX_CONTENT_LENGTH and add file upload size limits across all HTTP entry points (tooling-trusted-releases)
via GitHub
Re: [I] Enforce MAX_CONTENT_LENGTH and add file upload size limits across all HTTP entry points (tooling-trusted-releases)
via GitHub
Re: [I] Evaluate ASVS v5.0.0 compliance: documentation (tooling-trusted-releases)
via GitHub
Re: [I] Evaluate ASVS v5.0.0 compliance: documentation (tooling-trusted-releases)
via GitHub
Re: [I] Evaluate ASVS v5.0.0 compliance: denial of service (tooling-trusted-releases)
via GitHub
Earlier messages
Later messages