Page MenuHomePhabricator

GitLab Private Repository Request for: WP-Civi security review
Closed, ResolvedPublicRequest

Description

  • The name of your repository: WP-Civi security review
  • The purpose of your repository: Share the source code of a WordPress plugin developed by a contractor with the WMF Security team, for them to perform their security review. This repository will be either made public, migrated or deleted after the security review is completed.
  • The username(s) of the owner(s) and maintainer(s) of your repository: @Qgil
  • Phabricator project where administrators should report any tasks related to your repository: This is a one-off repository in my personal namespace and I don't have a Phabricator project for it. I can create a corresponding Phabricator project for it if needed.
  1. Please check the box to agree and acknowledge the following:
    • All owners and maintainers have GitLab 2fa enabled and are using strong passwords
    • Private repositories are only for restricted information, not confidential information
    • Accept the risks associated with private repositories, e.g.:
      • Configuration changes – Any repository owner may change the visibility of your repository
      • Forks – Anyone with the ability to fork your repo may change settings on their fork and expose information
      • Forge vulnerabilities – GitLab may have an unknown vulnerability that may leak information contained within or metadata about this repository

Event Timeline

brennen claimed this task.
brennen subscribed.

Seems like it fits the rubric ok. I couldn't figure out how to change the privacy level of a repo in your namespace, so I instead made this one in the namespace we recently created for one-off projects that don't fit anywhere else:

https://gitlab.wikimedia.org/repos/projects/wp-civi-security-review

Set Qgil as owner.

Thank you very much! That works.

  NODES
admin 1
Note 1
Project 6