As per the Security Advisory,
https://www.drupal.org/security-advisory-policy
this module which is considered currently to be a release candidate can be brought up to standards.
| Comment | File | Size | Author |
|---|---|---|---|
| #7 | pareview_fixes-2861362-7.patch | 4.34 KB | mikebrooks |
Comments
Comment #2
darrell_ulm commentedComment #3
darrell_ulm commentedAlso for module users, it can be decided to Opt-In in the project edit screen.
It states:
Here is the security advisory coverage: https://www.drupal.org/security-advisory-policy
Have been working more in Apache Spark and other projects recently as a heads up.
Comment #4
mikebrooks commentedHi Darrell,
I am not security vetted yet, though I have an application in the issue queue for another project.
Prerequisite to Security Advisory Coverage is a stable release, i.e. not dev, alpha, beta, or rc.
Given the lack of bugs, I see no reason why we can't change the branch to 7.x-1.0.
Can you make the release update?
Comment #5
mikebrooks commentedPlease ignore my prior post... just ran PAReview. Lots of issues (see below).
I can work on the issues when I have some free time. They look pretty straight forward.
Review of the 7.x-1.x branch (commit 1f3862d):
This automated report was generated with PAReview.sh, your friendly project application review script. You can also use the online version to check your project. You have to get a review bonus to get a review from me.
Comment #6
darrell_ulm commentedYes, good idea running PAReview!
They will want to have about everything clean before we apply for the security coverage.
Surprised there were some unused variables in there, but totally possible.
Yes on
once it runs through clean, and has the same functionality, which it should with the above fixes.
Then we can go stable and submit.
Thank you again.
Comment #7
mikebrooks commentedI am attaching a patch that should resolve the problems raised by PAReview.sh. The coder module indicates all problems are resolved in my local dev environment. I have conducted basic testing of the module. Another set of eyes would be helpful to confirm the update.
If there is no review within 48 hours, I'll commit the changes to the dev branch, unless someone thinks I should give it more time.
Comment #8
darrell_ulm commentedReviewed, this looks good, anyone who has access can commit when ready, thank you!
Comment #9
mikebrooks commentedThanks Darrell,
I'll commit to the Dev branch tonight. I don't believe that I have rights to create a release, however. I can ask Nishad, or you can take care of it if you have time.
Cheers - Mike
Comment #10
darrell_ulm commentedThanks @mikebrooks , I should be able to make the 7.x-1.0 release.
Comment #12
mikebrooks commentedPatch committed to the 7.x-1.x branch.
Comment #13
mikebrooks commentedApparently, PAReview is more particular than the coder module. Some more issues to correct.
Comment #18
mikebrooks commentedHi Darrell,
This is as good as it is going to get right now. Feel free to create a stable release.
Comment #19
darrell_ulm commentedOK, the release is made and live, and opt-ed into the policy. Noticed that in the time the policy came out, there was a 60% usage drop, perhaps that was the reason as there were no other reports in the issue queue.
Comment #20
darrell_ulm commented