Loading...
 

The Security Team is a trusted group. This team is responsible to review security reports and to proceed to a pro-active audit at each major release. Security Team members are added by vote by the Admins following recommendations of current members.

Release responsibilities

  1. Review all previously reported issues on dev & sent to security list.
    1. Ask bug reporters how they would like to be acknowledged.
  2. Contact all people that have helped in the past.
  3. Proceed to security audit as per our release procedures.
    • run doc/devtools/securitycheck.php and check each "potentially unsafe" file.
    • Check for presence of all .htaccess files
    • Add files to robots.txt (printed pages, etc.)
  4. Update security.tiki.org with sections for new version
  5. Run Security DB

Ongoing responsibilities

Coordinator

  • The security team coordinator is Brendan Ferguson (drsassafras)
    • All disclosures are in the tracker and followed up in a timely fashion
    • Makes sure proper credit is given to researchers for responsible disclosures

Task

  • Document how to run SecDB for people running from SVN

Members

Alias

Contributors to this page: marclaporte .
Page last modified on Sunday 25 February 2018 03:06:10 CET.