-
-
Notifications
You must be signed in to change notification settings - Fork 1.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Proposal to remove the reward/gift aspect for vulnerabilities #5940
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
jenkins-infra/board Do you want to discuss the topic more broadly?
Fine with me to keep this conversation here on the PR, the impact is surveyable.
+1 for removing the gift policy, if there's no demand for it.
I also see no special need in such policy. As an alternative that would be
more beneficial to the community, we can register a "Jenkins security
contributor" OpenBadge with the Linux Foundation and give it to the
reporters of valid issues that we include into the advisories. I can help
you with having it set up.
Believe that such a badge could be more interesting than monetary reward,
especially thanks to open badge in service integrations with LinkedIn and
Co. It would also help with the project visibility
…On Fri, 20 Jan 2023, 13:44 Alexander Brandes, ***@***.***> wrote:
***@***.**** approved this pull request.
jenkins-infra/board Do you want to discuss the topic more broadly?
Fine with me to keep this conversation here on the PR, the impact is
surveyable.
+1 for removing the gift policy, if there's no demand for it.
—
Reply to this email directly, view it on GitHub
<#5940 (review)>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/AAW4RIDN7K742WITAM2SVYTWTKCBVANCNFSM6AAAAAAUBLSD5E>
.
You are receiving this because you are on a team that was mentioned.Message
ID: ***@***.***>
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I like the change. Thanks very much!
@daniel-beck with 3 board members approving, this will be merged to remove the gift text |
@@ -1,65 +0,0 @@ | |||
--- |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Time to figure out how to purge the site?
https://www.jenkins.io/security/gift/
Even the search still indexes it…
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I've ran curl -X PURGE https://www.jenkins.io/security/gift
and a complete purge on Fastly but the page is still present 🤷
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
It seems the page is still in the bucket:
curl -v -H "Host: www.jenkins.io" https://www.origin.jenkins.io/security/gift/
I'll open an helpdesk issue to figure this out.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Yep, we only add, never delete.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Issue opened: jenkins-infra/helpdesk#3360
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Yep, we only add, never delete.
Do you happen to know the reason for that?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
My guess (!) is that we just upload using the Azure CLI and never delete what's there.
Context
Opinion
@daniel-beck WDYT?
@jenkins-infra/board Do you want to discuss the topic more broadly?