Release responsibilities

  1. Review all previously reported issues on dev & sent to security list.
    1. Ask bug reporters how they would like to be acknowledged.
  2. Contact all people that have helped in the past.
  3. Proceed to security audit as per our release procedures.
    • run doc/devtools/securitycheck.php and check each "potentially unsafe" file.
    • Check for presence of all .htaccess files
    • Add files to robots.txt (printed pages, etc.)
  4. Update security.tiki.org with sections for new version
  5. Run Security DBQuestion

Ongoing responsibilities


  • The security team coordinator is Brendan Ferguson (drsassafras)
    • All disclosures are in the tracker and followed up in a timely fashion
    • Makes sure proper credit is given to researchers for responsible disclosures


  • Document how to run SecDB for people running from SVN
    • SecDB update is incorporated into doc/devtools/svnup.php now (since Tiki 16 i think )


Team Security


Created by: Last Modification: Tuesday 12 June 2018 15:57:07 GMT-0000 by Jonny Bradley
List Slides