Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Check the wiki & codebase for mentions of security@edx.org/@tcril.org and update it to security@openedx.org #15

Closed
Tracked by #13
feanil opened this issue Feb 22, 2023 · 8 comments
Assignees

Comments

@feanil
Copy link

feanil commented Feb 22, 2023

Also update any mentions of security@tcril.org to security@openedx.org

As of 2023-03-10, this includes in our codebases:

% allgit - grep "security@tcril.org" | allgit2tsv
course-discovery	README.rst:Please do not report security issues in public. Please email security@tcril.org.
edx-ace	README.rst:Please do not report security issues in public. Please email security@tcril.org.
edx-cookiecutters	python-template/{{cookiecutter.placeholder_repo_name}}/README.rst:Please do not report security issues in public. Please email security@tcril.org.
edx-developer-docs	README.rst:Please do not report security issues in public. Please email security@tcril.org
edx-enterprise-subsidy-client	README.rst:Please do not report security issues in public. Please email security@tcril.org.
edx-rest-api-client	README.rst:Please do not report security issues in public. Please email security@tcril.org.
enterprise-subsidy	README.rst:Please do not report security issues in public. Please email security@tcril.org.
event-bus-redis	README.rst:Please do not report security issues in public. Please email security@tcril.org.
frontend-app-learner-record	README.rst:Please do not report security issues in public. Please email security@tcril.org.
openedx-events	README.rst:Please do not report security issues in public. Please email security@tcril.org.
openedx-filters	README.rst:Please do not report security issues in public. Please email security@tcril.org.
openedx-ledger	README.rst:Please do not report security issues in public. Please email security@tcril.org.
token-utils	README.rst:Please do not report security issues in public. Please email security@tcril.org.
xapi-db-load	README.rst:Please do not report security issues in public. Please email security@tcril.org.
xblock-lti-consumer	README.rst:Please do not report security issues in public. Please email security@tcril.org.
xblock-skill-tagging	README.rst:Please do not report security issues in public. Please email security@tcril.org.

Reasoning

For any security issues with the Open edX Platform codebase, they should go to security@openedx.org which will be handled by the openedx security working group. The security@tcril.org or security@axim.org addresses should be used for reporting issues with resources owned by Axim that are not a part of the Open edX codebase.

@pshiu pshiu changed the title Check the wiki for mentions of security@edx.org and update it to security@openedx.org Check the wiki & codebase for mentions of security@edx.org and update it to security@openedx.org Mar 10, 2023
@pshiu pshiu changed the title Check the wiki & codebase for mentions of security@edx.org and update it to security@openedx.org Check the wiki & codebase for mentions of security@edx.org/@tcril.org and update it to security@openedx.org Mar 10, 2023
@timmc-edx
Copy link

I also see a mention on https://openedx.org/community/connect/

@MAAngamarca
Copy link

Hi, I'm going to work on this issue.

@feanil
Copy link
Author

feanil commented May 4, 2023

@MAAngamarca sounds good, let me know if you have any questions! I've assigned this to you for now.

@nedbat
Copy link

nedbat commented Jun 6, 2023

Just for clarity: now that axim.org is a thing, the address should still be security@openedx.org?

@feanil
Copy link
Author

feanil commented Jun 12, 2023

@nedbat yes, we're trying to use the openedx.org address as the new address instead of the axim one. This makes it easier to separate the security issues related to axim the company from security issues related to the Open edX Project.

@feanil
Copy link
Author

feanil commented Jul 26, 2023

@MAAngamarca have you had time to work on this? I don't know if I've missed the relevant PRs. If not, should someone else pick this up?

@MAAngamarca
Copy link

@feanil Sorry, I forgot to change in all repositories, but I just did.

feanil added a commit to openedx/aspects-dbt that referenced this issue Aug 1, 2023
Use the openedx security e-mail address instead of the Axim One.

See openedx/wg-security#15 for details.
feanil added a commit to openedx/openedx-tutor-plugins that referenced this issue Aug 1, 2023
arbrandes pushed a commit to openedx/openedx-tutor-plugins that referenced this issue Aug 1, 2023
@feanil
Copy link
Author

feanil commented Aug 1, 2023

I've checked the ORG and updated the openedx.org site. This should be all set now, thank you @MAAngamarca!

@feanil feanil closed this as completed Aug 1, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Archived in project
Development

No branches or pull requests

4 participants