Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Why are Github security advisors not used? #1439

Closed
Warmek opened this issue Apr 20, 2023 · 11 comments
Closed

Why are Github security advisors not used? #1439

Warmek opened this issue Apr 20, 2023 · 11 comments
Labels
question Any question about leshan

Comments

@Warmek
Copy link
Contributor

Warmek commented Apr 20, 2023

Question

I can see here: https://github.com/eclipse/leshan/security/policy that Github security advisors are not used. Why is that?

@Warmek Warmek added the question Any question about leshan label Apr 20, 2023
@sbernard31
Copy link
Contributor

sbernard31 commented Apr 20, 2023

It sounds not possible if we are under Eclipse Github Organization, see https://gitlab.eclipse.org/eclipsefdn/helpdesk/-/issues/449 for more details.

Note that maybe it would be possible by moving Leshan under a dedicated organization : https://gitlab.eclipse.org/eclipsefdn/helpdesk/-/issues/1705

@Warmek
Copy link
Contributor Author

Warmek commented May 11, 2023

What benefits would the use of security advisors bring for Leshan?

@sbernard31
Copy link
Contributor

sbernard31 commented May 11, 2023

Mainly :

You can use repository security advisories to privately discuss, fix, and publish information about security vulnerabilities in your repository.

(source : https://docs.github.com/en/code-security/security-advisories/repository-security-advisories/about-repository-security-advisories)

@sbernard31
Copy link
Contributor

Eclipse IT Team ask us if we want to move to our own organization that way we will be able to enable GitHub security advisories for Leshan : https://gitlab.eclipse.org/eclipsefdn/helpdesk/-/issues/449#note_1115464

@Warmek, @jvermillard, @JaroslawLegierski any opinion about this ?

@sbernard31
Copy link
Contributor

Regarding answers provided by Eclipse Team.
I plan to ask us to move Leshan in its own organization to have access to GitHub security advisories.

I will probably give them the green light next week.
So @Warmek, @jvermillard, @JaroslawLegierski, you have until the end of the week :

  • to let me know if you think this is a bad idea
  • OR to ask me more time to think about it. (On my side there is no urgency, so do not hesitate)

@jvermillard
Copy link
Contributor

👍

@Warmek
Copy link
Contributor Author

Warmek commented Jun 15, 2023

The only thing that we need is for https://github.com/eclipse/leshan url to be working and redirect to https://github.com/eclipse-leshan/leshan

@sbernard31
Copy link
Contributor

sbernard31 commented Jun 15, 2023

The only thing that we need is for https://github.com/eclipse/leshan url to be working and redirect to https://github.com/eclipse-leshan/leshan

This should be done : Regarding answers provided by Eclipse Team.

@sbernard31
Copy link
Contributor

I give the green light to eclipse for the move : https://gitlab.eclipse.org/eclipsefdn/helpdesk/-/issues/449#note_1153533

@sbernard31
Copy link
Contributor

sbernard31 commented Jun 27, 2023

leshan project was moved to its own eclipse-leshan organization that means that security advisors will be available soon are now available.

I will update the SECURITY.MD file then I think we will be able to close this issue ?

@sbernard31
Copy link
Contributor

SECURITY.MD is updated (commit a356488).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
question Any question about leshan
Projects
None yet
Development

No branches or pull requests

3 participants