-
Notifications
You must be signed in to change notification settings - Fork 113
Conversation
@geek thanks for making this go. I apologize for not being able to touch up the various suggestions. This is great. |
@evilpacket I just want to make sure you can say that node at least has a security page when you present at node summit! |
@@ -0,0 +1 @@ | |||
{ "template": "doc/about.html", "title": "Security" } |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
missing newline
small issue: please add the link also to: https://github.com/joyent/node-website/blob/master/doc/about/advisory-board/template.html#L37-L46 - the advisory board has an own template |
+1 after adressing the minor nits I found, great work everybody! |
@robertkowalski all fixed up |
+1 |
merge it! :) |
security: Adding page to about section
|
||
- The security report is received and is assigned a primary handler. This person will coordinate the fix and release | ||
process. The problem is confirmed and a list of all affected versions is determined. Code is audited to find any | ||
potential similar problems. Fixes are prepared for all releases which are still under maintenance. These fixes are not |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Regarding
Fixes are prepared for all releases which are still under maintenance
Are the releases under maintenance documented somewhere? It is confusing for some users at least, so I think we should probably have that information easily available on the website.
@evilpacket @geek @robertkowalski Thank you! |
@geek @robertkowalski I don't see the security page online. When is the next upload/deploy scheduled for the website? |
@misterdjules trying to determine if I need the core teams approval first. @tjfontaine do you know if I can just upload the new security page? |
I think this is fine, the content is fairly non-controversial and the truth -- I say go for it. In general my opinion is you don't need to seek core team approval unless you think it's changing process for the core team. But we will discuss on the call tomorrow. |
The site is updated, the security page is published: http://nodejs.org/about/security/ |
@geek @robertkowalski @evilpacket Thanks again 👍 |
Content comes from @evilpacket in PR #60