Re: Add security.txt file to php.net
| From: | Ben Ramsey | Date: | Fri, 29 Sep 2023 18:31:12 +0000 |
| Subject: | Re: Add security.txt file to php.net | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-121184@lists.php.net to get a copy of this message | ||
On 9/29/23 08:42, Sara Golemon wrote:
Attachment: [application/pgp-signature] OpenPGP digital signature OpenPGP_signature.asc
On Thu, Sep 28, 2023 at 5:20 PM Ben Ramsey <ramsey@php.net> wrote:I didn't like having them in theI've added documentation inline in the security.txt fileTo add some nitpicky bikeshedding, I'd put those instructions elsewhere (maybe php-src:docs/release-process.md ?) and only have a single line in the security.txt file referring out to that. The focus of the security.txt file should BE the metadata. +1 on the concept, and I do like the idea of making it part of the new branch release process as well as having one of the new RMs being the ones to sign it. -Sara
security.txt file, either, but I wasn't sure where to put them, since they're technically not part of the release process.
I've updated my PR here: https://github.com/php/php-src/pull/12316
It has the instructions in a separate docs/security-policies.md file:
https://github.com/ramsey/php-src/blob/security-txt/docs/security-policies.md
The release-process.md doc is amended here (in that same PR):
https://github.com/ramsey/php-src/blob/security-txt/docs/release-process.md#preparing-for-the-initial-stable-version-php-xy0
And the security.txt file in web-php now looks like this:
https://github.com/ramsey/web-php/blob/security-txt/.well-known/security.txt
Cheers,
Ben
Attachment: [application/pgp-signature] OpenPGP digital signature OpenPGP_signature.asc