mirror of
https://github.com/PowerShell/PowerShell
synced 2026-06-08 12:12:50 +00:00
update processes to allow for coordinated vulnerability disclosure (#6042)
This commit is contained in:
@@ -98,6 +98,8 @@ Additional references:
|
||||
|
||||
#### Before submitting
|
||||
|
||||
* If your change would fix a security vulnerability,
|
||||
first follow the [vulnerability issue reporting policy][vuln-reporting], before submitting a PR.
|
||||
* To avoid merge conflicts, make sure your branch is rebased on the `master` branch of this repository.
|
||||
* Many code changes will require new tests,
|
||||
so make sure you've added a new test if existing tests do not effectively test the code changed.
|
||||
@@ -299,6 +301,7 @@ Once you sign a CLA, all your existing and future pull requests will be labeled
|
||||
[testing-guidelines]: ../docs/testing-guidelines/testing-guidelines.md
|
||||
[running-tests-outside-of-ci]: ../docs/testing-guidelines/testing-guidelines.md#running-tests-outside-of-ci
|
||||
[issue-management]: ../docs/maintainers/issue-management.md
|
||||
[vuln-reporting]: ../docs/maintainers/issue-management.md#Security-Vulnerabilities
|
||||
[governance]: ../docs/community/governance.md
|
||||
[using-prs]: https://help.github.com/articles/using-pull-requests/
|
||||
[fork-a-repo]: https://help.github.com/articles/fork-a-repo/
|
||||
|
||||
@@ -1,8 +1,14 @@
|
||||
# Issue Management
|
||||
|
||||
## Security Vulnerabilities
|
||||
|
||||
If you believe that there is a security vulnerability in PowerShell Core,
|
||||
it **must** be reported to [secure@microsoft.com](https://technet.microsoft.com/en-us/security/ff852094.aspx) to allow for [Coordinated Vulnerability Disclosure](https://technet.microsoft.com/en-us/security/dn467923).
|
||||
**Only** file an issue, if secure@microsoft.com has confirmed filing an issue is appropriate.
|
||||
|
||||
## Long-living issue labels
|
||||
=======
|
||||
## Issue and PR Labels
|
||||
|
||||
### Issue and PR Labels
|
||||
|
||||
Issues are opened for many different reasons.
|
||||
We use the following labels for issue classifications:
|
||||
@@ -61,6 +67,7 @@ These labels describe what feature area of PowerShell that an issue affects:
|
||||
### Operating Systems
|
||||
|
||||
These are for issues that are specific to certain Operating Systems:
|
||||
|
||||
* `OS-Linux`
|
||||
* `OS-macOS`
|
||||
* `OS-Windows`
|
||||
|
||||
@@ -14,7 +14,7 @@ This is to help track the release preparation work.
|
||||
|
||||
> Note: Step 2, 3 and 4 can be done in parallel.
|
||||
|
||||
1. Create a branch named `release` in `PowerShell/PowerShell` repository.
|
||||
1. Create a branch named `release-<Release Tag>` in our private repository.
|
||||
All release related changes should happen in this branch.
|
||||
1. Prepare packages
|
||||
- [Build release packages](#building-packages).
|
||||
@@ -28,7 +28,7 @@ This is to help track the release preparation work.
|
||||
1. [Create NuGet packages](#nuget-packages) and publish them to [powershell-core feed][ps-core-feed].
|
||||
1. [Create the release tag](#release-tag) and push the tag to `PowerShell/PowerShell` repository.
|
||||
1. Create the draft and publish the release in Github.
|
||||
1. Merge the `release` branch to `master` and delete the `release` branch.
|
||||
1. Merge the `release-<Release Tag>` branch to `master` in `powershell/powershell` and delete the `release-<Release Tag>` branch.
|
||||
1. Publish Linux packages to Microsoft YUM/APT repositories.
|
||||
1. Trigger the release docker builds for Linux and Windows container images.
|
||||
- Linux: push a branch named `docker` to `powershell/powershell` repository to trigger the build at [powershell docker hub](https://hub.docker.com/r/microsoft/powershell/builds/).
|
||||
|
||||
@@ -72,19 +72,19 @@ Describe 'Common Tests - Validate Markdown Files' -Tag 'CI' {
|
||||
try
|
||||
{
|
||||
$docsToTest = @(
|
||||
'./.github/CONTRIBUTING.md'
|
||||
'./*.md'
|
||||
'./demos/SSHRemoting/*.md'
|
||||
'./docker/*.md'
|
||||
'./docs/*.md'
|
||||
'./docs/building/*.md'
|
||||
'./docs/cmdlet-example/*.md'
|
||||
'./docs/git/submodules.md'
|
||||
'./docs/installation/*.md'
|
||||
'./docs/maintainers/README.md'
|
||||
'./docs/maintainers/*.md'
|
||||
'./docs/testing-guidelines/testing-guidelines.md'
|
||||
'./demos/SSHRemoting/*.md'
|
||||
'./docker/*.md'
|
||||
'./test/powershell/README.md'
|
||||
'./tools/*.md'
|
||||
'./.github/CONTRIBUTING.md'
|
||||
)
|
||||
$filter = ($docsToTest -join ',')
|
||||
&"gulp" test-mdsyntax --silent `
|
||||
|
||||
Reference in New Issue
Block a user