Page MenuHomePhabricator

Security PreviewComponent
ActivePublic

Members (1)

Watchers

  • This project does not have any watchers.
  • View All

Details

Description

Requests for Security-Team input during the planning phase. See the SOP for expectations of maturity before engaging this service, for later phases, see Application Security Reviews).

Read: https://www.mediawiki.org/wiki/Security/SOP/Security_Preview

Part of Security-Team. Workboard is tracked at secscrum.

Neueste Aktivität

Wed, Jul 31

sbassett added a comment to T367995: Security Preview for shared login domain.

Do you mean the shared login domain specifically or the SUL3 project in general? (I'll file another security preview request about T363699: Determine and implement SUL 3 login handshake mechanism in a day or two, once I have PoC code. I think these are the two particularly security-sensitive parts of the project, the rest of the work is less interesting.)

Wed, Jul 31, 5:29 PM · SecTeam-Processed, secscrum, SUL3, Security Preview, RFS

Mon, Jul 29

Krinkle updated the task description for T367995: Security Preview for shared login domain.
Mon, Jul 29, 6:44 PM · SecTeam-Processed, secscrum, SUL3, Security Preview, RFS

Wed, Jul 24

Tgr updated subscribers of T367995: Security Preview for shared login domain.

Do you mean the shared login domain specifically or the SUL3 project in general? (I'll file another security preview request about T363699: Determine and implement SUL 3 login handshake mechanism in a day or two, once I have PoC code. I think these are the two particularly security-sensitive parts of the project, the rest of the work is less interesting.)

Wed, Jul 24, 10:29 PM · SecTeam-Processed, secscrum, SUL3, Security Preview, RFS
sbassett added a comment to T367995: Security Preview for shared login domain.

Hey @Tgr - I'd like to set up an initial threat-modeling/concept-review session (or two) for this work with you and any other relevant folks, this quarter. Are there any other technical folks that you're aware of who would likely be helpful during or interested in participating in such exercises? Thanks.

Wed, Jul 24, 4:20 PM · SecTeam-Processed, secscrum, SUL3, Security Preview, RFS

Tue, Jul 16

Tgr added a comment to T367995: Security Preview for shared login domain.

The configuration is now live in the beta cluster - the domain is not used for anything yet, but it works.
Example of an allowed request: https://sso.wikimedia.beta.wmflabs.org/en.wikipedia.beta.wmflabs.org/wiki/Special:UserLogin
Example of a disallowed request: https://sso.wikimedia.beta.wmflabs.org/en.wikipedia.beta.wmflabs.org/wiki/Main_Page

Tue, Jul 16, 7:35 PM · SecTeam-Processed, secscrum, SUL3, Security Preview, RFS

Tue, Jul 9

Tgr changed the visibility for T367995: Security Preview for shared login domain.
Tue, Jul 9, 8:44 AM · SecTeam-Processed, secscrum, SUL3, Security Preview, RFS
Tgr added a comment to T367995: Security Preview for shared login domain.

Does this need to be security protected?

Tue, Jul 9, 8:43 AM · SecTeam-Processed, secscrum, SUL3, Security Preview, RFS

Mon, Jul 8

Tgr updated subscribers of T367995: Security Preview for shared login domain.
Mon, Jul 8, 10:04 PM · SecTeam-Processed, secscrum, SUL3, Security Preview, RFS

Jul 3 2024

sbassett removed projects from T367123: Investigate minio packaging, install, security monitoring.: secscrum, RFS.
Jul 3 2024, 5:17 PM · SecTeam-Processed, Privacy Engineering, Security Preview
sbassett removed projects from T368108: Investigate Superset packaging, install, security monitoring.: secscrum, RFS.
Jul 3 2024, 5:15 PM · SecTeam-Processed, Privacy Engineering, Security Preview
sbassett removed projects from T367817: Investigate Dagster packaging, install, security monitoring.: secscrum, RFS.
Jul 3 2024, 5:15 PM · SecTeam-Processed, Privacy Engineering, Security Preview
sbassett removed projects from T367818: Investigate Trino/Starburst install, operation and maintenance, and security monitoring.: secscrum, RFS.
Jul 3 2024, 5:15 PM · SecTeam-Processed, Privacy Engineering, Security Preview
sbassett changed the status of T367995: Security Preview for shared login domain from Open to In Progress.
Jul 3 2024, 5:13 PM · SecTeam-Processed, secscrum, SUL3, Security Preview, RFS
sbassett moved T367995: Security Preview for shared login domain from Upcoming Quarter Planning Queue to In Progress on the secscrum board.
Jul 3 2024, 5:12 PM · SecTeam-Processed, secscrum, SUL3, Security Preview, RFS

Jun 28 2024

Tgr moved T367995: Security Preview for shared login domain from Backlog to Blocked / External on the SUL3 board.
Jun 28 2024, 1:10 PM · SecTeam-Processed, secscrum, SUL3, Security Preview, RFS

Jun 27 2024

Jgreen updated the task description for T367818: Investigate Trino/Starburst install, operation and maintenance, and security monitoring..
Jun 27 2024, 10:04 PM · SecTeam-Processed, Privacy Engineering, Security Preview
Jgreen updated the task description for T367818: Investigate Trino/Starburst install, operation and maintenance, and security monitoring..
Jun 27 2024, 10:03 PM · SecTeam-Processed, Privacy Engineering, Security Preview
Jgreen renamed T367818: Investigate Trino/Starburst install, operation and maintenance, and security monitoring. from Investigate starburst(trino) install, operation and maintenance, and security monitoring. to Investigate Trino/Starburst install, operation and maintenance, and security monitoring..
Jun 27 2024, 10:02 PM · SecTeam-Processed, Privacy Engineering, Security Preview

Jun 26 2024

Jgreen added a comment to T367817: Investigate Dagster packaging, install, security monitoring..

Updated list:

Jun 26 2024, 7:00 PM · SecTeam-Processed, Privacy Engineering, Security Preview

Jun 24 2024

sbassett edited projects for T367995: Security Preview for shared login domain, added: SecTeam-Processed; removed Security-Team.
Jun 24 2024, 4:11 PM · SecTeam-Processed, secscrum, SUL3, Security Preview, RFS
sbassett moved T368108: Investigate Superset packaging, install, security monitoring. from Incoming to Upcoming Quarter Planning Queue on the secscrum board.
Jun 24 2024, 3:08 PM · SecTeam-Processed, Privacy Engineering, Security Preview

Jun 20 2024

Jgreen added a comment to T367817: Investigate Dagster packaging, install, security monitoring..

For Debian Bullseye, the following pip packages get installed to the Dagster venv:

Jun 20 2024, 8:23 PM · SecTeam-Processed, Privacy Engineering, Security Preview
Jgreen renamed T367817: Investigate Dagster packaging, install, security monitoring. from Investigate dagster packaging, install, security monitoring. to Investigate Dagster packaging, install, security monitoring..
Jun 20 2024, 8:22 PM · SecTeam-Processed, Privacy Engineering, Security Preview
Jgreen added a comment to T368108: Investigate Superset packaging, install, security monitoring..

For Debian Bullseye, the following packages get installed to the Superset venv:

Jun 20 2024, 8:20 PM · SecTeam-Processed, Privacy Engineering, Security Preview
Jgreen created T368108: Investigate Superset packaging, install, security monitoring..
Jun 20 2024, 8:16 PM · SecTeam-Processed, Privacy Engineering, Security Preview
sbassett moved T367995: Security Preview for shared login domain from Incoming to Upcoming Quarter Planning Queue on the secscrum board.
Jun 20 2024, 3:46 PM · SecTeam-Processed, secscrum, SUL3, Security Preview, RFS
Tgr added a comment to T367995: Security Preview for shared login domain.

Probably not? I used the link at https://www.mediawiki.org/wiki/Security/SOP/Security_Preview and that created it like that.

Jun 20 2024, 11:25 AM · SecTeam-Processed, secscrum, SUL3, Security Preview, RFS
Reedy added a comment to T367995: Security Preview for shared login domain.

Does this need to be security protected?

Jun 20 2024, 11:12 AM · SecTeam-Processed, secscrum, SUL3, Security Preview, RFS

Jun 19 2024

Tgr added a parent task for T367995: Security Preview for shared login domain: T363695: Create a Wikimedia login domain that can be served by any wiki.
Jun 19 2024, 8:48 PM · SecTeam-Processed, secscrum, SUL3, Security Preview, RFS
Tgr created T367995: Security Preview for shared login domain.
Jun 19 2024, 8:47 PM · SecTeam-Processed, secscrum, SUL3, Security Preview, RFS

Jun 17 2024

sbassett moved T367817: Investigate Dagster packaging, install, security monitoring. from Incoming to Upcoming Quarter Planning Queue on the secscrum board.
Jun 17 2024, 9:10 PM · SecTeam-Processed, Privacy Engineering, Security Preview
sbassett moved T367818: Investigate Trino/Starburst install, operation and maintenance, and security monitoring. from Incoming to Upcoming Quarter Planning Queue on the secscrum board.
Jun 17 2024, 9:10 PM · SecTeam-Processed, Privacy Engineering, Security Preview
Jgreen created T367818: Investigate Trino/Starburst install, operation and maintenance, and security monitoring..
Jun 17 2024, 8:58 PM · SecTeam-Processed, Privacy Engineering, Security Preview
Jgreen added a comment to T367123: Investigate minio packaging, install, security monitoring..

There's a script in the internal frack "packages" repository that fetches the package and reports the portion of changelog associated with the latest package. The deb package is then added to the frack internal repository using "reprepro includedeb".

Jun 17 2024, 8:43 PM · SecTeam-Processed, Privacy Engineering, Security Preview
Jgreen added a comment to T367817: Investigate Dagster packaging, install, security monitoring..

The basic install of dagster and its dependencies has been puppetized. Puppet also configures a pip-audit script to check for updates in the virtualenv and emails with success (clean audit) or an alert (patches are available). There's no project configuration in puppet yet, this part will be developed with BDC.

Jun 17 2024, 8:37 PM · SecTeam-Processed, Privacy Engineering, Security Preview
Jgreen updated the task description for T367817: Investigate Dagster packaging, install, security monitoring..
Jun 17 2024, 8:35 PM · SecTeam-Processed, Privacy Engineering, Security Preview
Jgreen created T367817: Investigate Dagster packaging, install, security monitoring..
Jun 17 2024, 8:35 PM · SecTeam-Processed, Privacy Engineering, Security Preview

Jun 12 2024

sbassett moved T367123: Investigate minio packaging, install, security monitoring. from Back Orders to Upcoming Quarter Planning Queue on the secscrum board.
Jun 12 2024, 4:12 PM · SecTeam-Processed, Privacy Engineering, Security Preview
sbassett moved T367123: Investigate minio packaging, install, security monitoring. from Incoming to Back Orders on the secscrum board.
Jun 12 2024, 4:07 PM · SecTeam-Processed, Privacy Engineering, Security Preview

Jun 11 2024

Jgreen added a comment to T367123: Investigate minio packaging, install, security monitoring..

More on vulnerability tracking. This isn't awesome but:

Jun 11 2024, 9:14 PM · SecTeam-Processed, Privacy Engineering, Security Preview
Jgreen added a comment to T367123: Investigate minio packaging, install, security monitoring..

https://github.com/minio/minio/security executive summary: watch the blog :-|

Jun 11 2024, 8:12 PM · SecTeam-Processed, Privacy Engineering, Security Preview

Jun 10 2024

Jgreen created T367123: Investigate minio packaging, install, security monitoring..
Jun 10 2024, 9:27 PM · SecTeam-Processed, Privacy Engineering, Security Preview

Jul 12 2023

Aklapper changed the edit policy for Security Preview.
Jul 12 2023, 8:17 AM

Apr 5 2022

sbassett changed the visibility for T297167: Security team input on Wikimedia Developer Portal static site.
Apr 5 2022, 4:52 PM · Application Security Reviews, secscrum, Wikimedia-Developer-Portal, Security Preview
Mstyles added a project to T297167: Security team input on Wikimedia Developer Portal static site: Application Security Reviews.
Apr 5 2022, 4:52 PM · Application Security Reviews, secscrum, Wikimedia-Developer-Portal, Security Preview

Mar 15 2022

sbassett closed T297167: Security team input on Wikimedia Developer Portal static site as Resolved.
Mar 15 2022, 2:24 PM · Application Security Reviews, secscrum, Wikimedia-Developer-Portal, Security Preview
sbassett moved T297167: Security team input on Wikimedia Developer Portal static site from In Progress to Our Part Is Done on the secscrum board.
Mar 15 2022, 2:23 PM · Application Security Reviews, secscrum, Wikimedia-Developer-Portal, Security Preview
Mstyles added a comment to T297167: Security team input on Wikimedia Developer Portal static site.

Security Review Summary - T297167 - 2022-03-14
Last commit reviewed: f6c0c04

Mar 15 2022, 1:33 AM · Application Security Reviews, secscrum, Wikimedia-Developer-Portal, Security Preview

Jan 11 2022

sbassett removed projects from T297167: Security team input on Wikimedia Developer Portal static site: RFS, Security-Team.
Jan 11 2022, 5:40 PM · Application Security Reviews, secscrum, Wikimedia-Developer-Portal, Security Preview
sbassett assigned T297167: Security team input on Wikimedia Developer Portal static site to Mstyles.
Jan 11 2022, 5:39 PM · Application Security Reviews, secscrum, Wikimedia-Developer-Portal, Security Preview