-
Notifications
You must be signed in to change notification settings - Fork 1
GSIP 129
Jody Garnett
The live developers guide is based off master, so the sooner we can correct the better :)
- Under Discussion
- In Progress
- Completed
- Rejected
- Deferred
In reviewing the developers guide a few sections are out of date:
- we have changed from roadmap planning to a time boxed release cycle
- cross link to to Release Cycle
- Update to quickstart to modern branches
- Correct GEOSERVER_DATA_DIR VM argument example
- We can use a section on "responsible disclosure" of security issues
- Push the code freeze back a month, and remove the RC2 release. This provides a bit more coding time each cycle and is a response to the lack of feedback on release candidates
- The result is a development cycle on master than ends with: beta, RC1 (code freeze), release
-
Clarify that fixes are expected to be back ported to the stable and maintenance branches (or what is the point of having them)
-
This will be a strong recommendation for now (rather than a requirement).
-
Initial patch/jira/pull request should be evaluated for
- Investigating if the issue impact all the active branches
- Investigating whether a fix is possible
- Capturing this in jira
Updating the build instructions and quickstart are a casual activity that should be able to proceed without formal change proposal.
Changing the following procedures are subject to review and approval by the PSC:
-
Removing the section on roadmap planning
-
Adding a section on responsible disclosure
- keep exploit details out of issue report
- send to developer/PSC privately (just like we do for sample data)
- be prepared to work with PSC members on a solution
- if you are unable to communicate in public/issue tracker please contact PSC members privately, or contact OSGeo at info@osgeogeo.org
- keep in mind PSC members are volunteers and an extensive fix may require fundraising / resources
-
We can also take the opportunity to refresh our PSC list based on activity
Discussion on reasonable disclosure:
- Handling of GEOS-7032: Remote File Disclosure - concerning XML External Entity XXE Processing and GEOS-7032
- Handling of a security flaw - concerning cross site scripting flaw
Project Steering Committee:
- Alessio Fabiani
- Andrea Aime
- Ben Caradoc-Davies
- Christian Mueller
- Gabriel Roldán
- Jody Garnett
- Jukka Rahkonen
- Justin Deoliveira
- Phil Scadden
- Simone Giannecchini
Committers:
©2020 Open Source Geospatial Foundation