The #indieweb module for #drupal is now in beta! Some smaller things can still go in, but what's left for a 1.0 release is a decent security review, anyone up for that ? :)


Chris Mcintosh on Sat, 20/10/2018 - 14:36

What's the current process for security reviews these days?

swentel on Sat, 20/10/2018 - 15:30

Not sure if there's really one, but I'll do one myself to begin with :)

Tatár Balázs János on Sat, 20/10/2018 - 16:26

I would love to help on it as at my work i do many sec audits, being involved in vuln management and being provisional member of drupal security team. DM me an issue where you expect my results (when d.o will be back)

swentel on Sat, 20/10/2018 - 16:26

Oh, that would be very nice. I currently track issues on GitHub - github.com/swentel/indiew… I think it's ok to handle them publicly at the moment - unless it's really really critical :)

Tatár Balázs János on Sat, 20/10/2018 - 22:16

if we see it from the disclosure policy of the drupal security team, all issues could be publicly handled as module is not released as a stable one :)

