From bd865280f36ea127414395d724cff1c778ddba73 Mon Sep 17 00:00:00 2001 From: Travis Plunk Date: Sat, 27 Jan 2018 10:28:33 -0800 Subject: [PATCH] update processes to allow for coordinated vulnerability disclosure (#6042) --- .github/CONTRIBUTING.md | 3 +++ docs/maintainers/issue-management.md | 11 +++++++++-- docs/maintainers/releasing.md | 4 ++-- test/common/markdown/markdown.tests.ps1 | 8 ++++---- 4 files changed, 18 insertions(+), 8 deletions(-) diff --git a/.github/CONTRIBUTING.md b/.github/CONTRIBUTING.md index 37e83f1ed5..7d00be5c8f 100644 --- a/.github/CONTRIBUTING.md +++ b/.github/CONTRIBUTING.md @@ -98,6 +98,8 @@ Additional references: #### Before submitting +* If your change would fix a security vulnerability, + first follow the [vulnerability issue reporting policy][vuln-reporting], before submitting a PR. * To avoid merge conflicts, make sure your branch is rebased on the `master` branch of this repository. * Many code changes will require new tests, so make sure you've added a new test if existing tests do not effectively test the code changed. @@ -299,6 +301,7 @@ Once you sign a CLA, all your existing and future pull requests will be labeled [testing-guidelines]: ../docs/testing-guidelines/testing-guidelines.md [running-tests-outside-of-ci]: ../docs/testing-guidelines/testing-guidelines.md#running-tests-outside-of-ci [issue-management]: ../docs/maintainers/issue-management.md +[vuln-reporting]: ../docs/maintainers/issue-management.md#Security-Vulnerabilities [governance]: ../docs/community/governance.md [using-prs]: https://help.github.com/articles/using-pull-requests/ [fork-a-repo]: https://help.github.com/articles/fork-a-repo/ diff --git a/docs/maintainers/issue-management.md b/docs/maintainers/issue-management.md index 13d6da4e59..a1778d2b76 100644 --- a/docs/maintainers/issue-management.md +++ b/docs/maintainers/issue-management.md @@ -1,8 +1,14 @@ # Issue Management +## Security Vulnerabilities + +If you believe that there is a security vulnerability in PowerShell Core, +it **must** be reported to [secure@microsoft.com](https://technet.microsoft.com/en-us/security/ff852094.aspx) to allow for [Coordinated Vulnerability Disclosure](https://technet.microsoft.com/en-us/security/dn467923). +**Only** file an issue, if secure@microsoft.com has confirmed filing an issue is appropriate. + ## Long-living issue labels -======= -## Issue and PR Labels + +### Issue and PR Labels Issues are opened for many different reasons. We use the following labels for issue classifications: @@ -61,6 +67,7 @@ These labels describe what feature area of PowerShell that an issue affects: ### Operating Systems These are for issues that are specific to certain Operating Systems: + * `OS-Linux` * `OS-macOS` * `OS-Windows` diff --git a/docs/maintainers/releasing.md b/docs/maintainers/releasing.md index f423ed25ac..c345acab29 100644 --- a/docs/maintainers/releasing.md +++ b/docs/maintainers/releasing.md @@ -14,7 +14,7 @@ This is to help track the release preparation work. > Note: Step 2, 3 and 4 can be done in parallel. -1. Create a branch named `release` in `PowerShell/PowerShell` repository. +1. Create a branch named `release-` in our private repository. All release related changes should happen in this branch. 1. Prepare packages - [Build release packages](#building-packages). @@ -28,7 +28,7 @@ This is to help track the release preparation work. 1. [Create NuGet packages](#nuget-packages) and publish them to [powershell-core feed][ps-core-feed]. 1. [Create the release tag](#release-tag) and push the tag to `PowerShell/PowerShell` repository. 1. Create the draft and publish the release in Github. -1. Merge the `release` branch to `master` and delete the `release` branch. +1. Merge the `release-` branch to `master` in `powershell/powershell` and delete the `release-` branch. 1. Publish Linux packages to Microsoft YUM/APT repositories. 1. Trigger the release docker builds for Linux and Windows container images. - Linux: push a branch named `docker` to `powershell/powershell` repository to trigger the build at [powershell docker hub](https://hub.docker.com/r/microsoft/powershell/builds/). diff --git a/test/common/markdown/markdown.tests.ps1 b/test/common/markdown/markdown.tests.ps1 index 00bfd7cdca..edd2648731 100644 --- a/test/common/markdown/markdown.tests.ps1 +++ b/test/common/markdown/markdown.tests.ps1 @@ -72,19 +72,19 @@ Describe 'Common Tests - Validate Markdown Files' -Tag 'CI' { try { $docsToTest = @( + './.github/CONTRIBUTING.md' './*.md' + './demos/SSHRemoting/*.md' + './docker/*.md' './docs/*.md' './docs/building/*.md' './docs/cmdlet-example/*.md' './docs/git/submodules.md' './docs/installation/*.md' - './docs/maintainers/README.md' + './docs/maintainers/*.md' './docs/testing-guidelines/testing-guidelines.md' - './demos/SSHRemoting/*.md' - './docker/*.md' './test/powershell/README.md' './tools/*.md' - './.github/CONTRIBUTING.md' ) $filter = ($docsToTest -join ',') &"gulp" test-mdsyntax --silent `