Skip to content

update with contents from https://www.linode.com/.well-known/security… - #10897

Closed
jschauma wants to merge 1 commit into
linode:developfrom
jschauma:develop
Closed

jschauma wants to merge 1 commit into
linode:developfrom
jschauma:develop

Conversation

@jschauma

@jschauma jschauma commented Sep 5, 2024

Copy link
Copy Markdown

@jschauma
jschauma requested a review from a team as a code owner September 5, 2024 17:55
@jschauma
jschauma requested review from hana-akamai and mjac0bs and removed request for a team September 5, 2024 17:55
@jschauma

jschauma commented Sep 5, 2024

Copy link
Copy Markdown
Author

Hi - I'm afraid I don't know what "missing changeset" means or what would be needed from my side here to move the PR forward, so I'm not sure if having it assigned to me is right.

@mjac0bs

mjac0bs commented Sep 5, 2024

Copy link
Copy Markdown
Contributor

Hi @jschauma - you beat me to making a comment to follow up here, thanks for monitoring this! In our public developer docs for contributors, we have a section on submitting a PR that explains the steps to add a changeset. Can you please follow those and add a Changed changeset? We also have a section on best practices for writing that changeset.

@github-actions

github-actions Bot commented Sep 5, 2024

Copy link
Copy Markdown

Coverage Report:
Base Coverage: 86.2%
Current Coverage: 86.2%

@jschauma

jschauma commented Sep 5, 2024

Copy link
Copy Markdown
Author

Hey @mjac0bs -- looks like creating this changeset requires me to install a bunch of tools like 'gh' and 'yarn', which I'm afraid seems like a lot of overkill for this simple text file only change. Any chance the PR can be reviewed without this? It's literally 15 lines of plain, English text, with no functional changes or markup anywhere.

@bnussman-akamai

Copy link
Copy Markdown
Member

I'm thinking we might want to migrate from security.txt to SECURITY.md based on this.

Not that it really matters, but it will help us improve on our community standards which will be satisfying
Screenshot 2024-09-05 at 3 51 13 PM

@bnussman-akamai bnussman-akamai left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Oh. I just realized this:

We should be updating packages/manager/public/.well-known/security.txt, not the root security.txt. The root security.txt is probably the one we should migrate to SECURITY.md

@hana-akamai

Copy link
Copy Markdown
Contributor

@jschauma Can you create a M3 ticket and provide some more context for this change?

@jschauma

jschauma commented Sep 5, 2024

Copy link
Copy Markdown
Author

I'm sorry, I don't know what an M3 ticket is either. :-)

The context for this PR is that the git repository currently has outdated contact information for Akamai's security team. The information I provided in this PR is the correct information that we want to use (and are already using as the .well-known/security.txt for akamai.com, linode.com, and noname.com at the very least). This should be consistent.

(Having a SECURITY.md file is a good idea, too; that should then also reflect the right contact information from the security.txt file.)

@mjac0bs

mjac0bs commented Sep 6, 2024

Copy link
Copy Markdown
Contributor

Thanks for the context, @jschauma. Based on that info and Banks' comments, I created a M3 ticket on the Cloud Manager team's internal board (searchable via M3-8548 - not linking it here since we generally keep links to internal resources off our public PRs).

I've picked up that ticket to make the changes based on the updated security information and added a changeset by branching off of develop. I'm going to close this PR in favor of #10902.

@jschauma

jschauma commented Sep 6, 2024

Copy link
Copy Markdown
Author

👍 - Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

4 participants