Well, I read release notes and reasoning behind it but I don't get why that 
breaking change wasn't made as opt-in. 

As I got it affects only build servers for open-source projects. But a lot 
of users with private Jenkins installation just got this update suddenly 
and had got broken workflow. I guess that usually maintainers of 
open-source projects are more advanced users and can enable extra 
protection for its server rather than other users had to do weird actions 
to make some Jenkins extensions back to work.

reede, 8. jaanuar 2016 17:24.04 UTC+3 kirjutas Daniel Beck:
>
> On 08.01.2016, at 11:49, Boris Serdiuk <[email protected]> wrote: 
>
> > Do you have any announcement or migration guide where I can redirect my 
> users? 
>
> Choose any of these, the full documentation is at most two clicks away: 
>
> Security advisory announcement: 
>
> https://groups.google.com/d/msg/jenkinsci-advisories/Zy8yMkQfld4/a8lkB_DUDQAJ 
>
> Announcement blog post: 
> https://jenkins-ci.org/blog/2015/12/09/security-updates-released-today/ 
>
> Regular changelog links to advisory: 
> https://jenkins-ci.org/changelog/#v1.641 
>
> LTS changelog links to advisory: 
> https://jenkins-ci.org/changelog-stable/#v1.625.3 
>
> Security advisory with giant notice on compatibility: 
>
> https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-12-09
>  
>
> Documentation: 
>
> https://wiki.jenkins-ci.org/display/JENKINS/Configuring+Content+Security+Policy
>  
>
> If you have suggestions how to make this more noticeable without doing 
> giant banners everywhere, or repeating the same information in a dozen 
> places, please let me know. 
>
> > Also, I looking for a better way to relax content security via UI rather 
> than change configuration properties in the file. 
>
> I'm planning to make setting the system property a regular part of the 
> Jenkins global security config UI. It is tracked here: 
> https://issues.jenkins-ci.org/browse/JENKINS-32296 
>
>

-- 
You received this message because you are subscribed to the Google Groups 
"Jenkins Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/jenkinsci-users/4c358304-8db8-45ee-8046-3a8e506d6697%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to