Closed (fixed)
Project:
Drupal.org security advisory coverage applications
Component:
module
Priority:
Critical
Category:
Task
Assigned:
Unassigned
Issue tags:
Reporter:
Created:
30 Jun 2017 at 12:52 UTC
Updated:
7 May 2018 at 11:34 UTC
Jump to comment: Most recent
Comments
Comment #2
sharma.amitt16 commentedComment #3
sharma.amitt16 commentedComment #4
PA robot commentedProject 1: https://www.drupal.org/node/2891185
Project 2: https://www.drupal.org/node/2874772
As successful completion of the project application process results in the applicant being granted the 'Create Full Projects' permission, there is no need to take multiple applications through the process. Once the first application has been successfully approved, then the applicant can promote other projects without review. Because of this, posting multiple applications is not necessary, and results in additional workload for reviewers ... which in turn results in longer wait times for everyone in the queue. With this in mind, your secondary applications have been marked as 'closed(duplicate)', with only one application left open (chosen at random).
If you prefer that we proceed through this review process with a different application than the one which was left open, then feel free to close the 'open' application as a duplicate, and re-open one of the project applications which had been closed.
I'm a robot and this is an automated message from Project Applications Scraper.
Comment #5
PA robot commentedFixed the git clone URL in the issue summary for non-maintainer users.
We are currently quite busy with all the project applications and we prefer projects with a review bonus. Please help reviewing and put yourself on the high priority list, then we will take a look at your project right away :-)
Also, you should get your friends, colleagues or other community members involved to review this application. Let them go through the review checklist and post a comment that sets this issue to "needs work" (they found some problems with the project) or "reviewed & tested by the community" (they found no major flaws).
I'm a robot and this is an automated message from Project Applications Scraper.
Comment #6
sharma.amitt16 commentedComment #7
sharma.amitt16 commentedComment #8
munish.kumar commentedHi @sharma.amitt16,
I've reviewed your module and it worked well for me. great work! Pareview.sh doesn't report any errors. This module also useful for drupal community so +1 from me.
Comment #9
sharma.amitt16 commentedComment #10
sharma.amitt16 commentedComment #11
dhayanandan_k commentedHi @sharma,
I have reviewed your module. It has no issues and the module is working.
Automated Review
No issues found by pareview.sh (https://pareview.sh/node/2574)
Manual Review
Individual user account
[Yes: Follows] the guidelines for individual user accounts
No duplication
[Yes: Does not cause] module duplication and/or fragmentation.
Master Branch
[Yes: Follows] the guidelines for master branch.
Licensing
[Yes: Follows] the licensing requirements.
3rd party assets/code
[Yes: Follows] the guidelines for 3rd party assets/code.
README.txt/README.md
[Yes: Follows] the guidelines for in-project documentation and/or the README Template.
Need to add Requirements and Configuration section
Code long/complex enough for review
[Yes: Follows] the guidelines for project length and complexity.
Secure code
[Yes: Meets the security requirements.]
Thanks,
Dhaya
Comment #12
sharma.amitt16 commentedThanks @dhayanandan_k for review.
Comment #13
sharma.amitt16 commentedAny Update for +RTBC ?
Comment #14
sharma.amitt16 commentedComment #15
sharma.amitt16 commentedI's over two months and no issue found but still no update about RTBC (Security Certified). Would anyone please update if I am doing anything wrong.
Comment #16
pranavgupta commentedHi @sharma.amitt16,
The module seems to work perfectly fine. Good work !! on the module.
but there seems to be some problem after using the module and then uninstalling the module from drush, Please check.
Comment #17
sharma.amitt16 commentedThanks @pranavgupta for reviewing the module.
There is no error on install/uninstall of the module using drush.
I have tested the scenario you described. If have you have created a field using this module, then there is a dependency of field on the module. In this case you can't uninstall the module, not even from UI. In this case, you need to delete the field first and then try to uninstall the module. Hope you will get success.
Please find the output I got after uninstall command using drush
The following extensions will be uninstalled: yearonly
Do you really want to continue? (y/n): y
yearonly was successfully uninstalled. [ok]
Please check in your case.
Thanks
Comment #18
sharma.amitt16 commentedHi,
Anyone please update for RTBC?
Comment #19
pranavgupta commentedHi sharma.amitt16,
looks good to me hence moving it to "RTBC".
Comment #20
sharma.amitt16 commentedThanks Pranav.
Comment #21
Anonymous (not verified) commentedI need such a module but Years Only isn't safe. When will it be safe?
Comment #22
sharma.amitt16 commentedThanks @20drei. Would you please provide security issues.
Comment #23
Anonymous (not verified) commentedOn the project's page, they say:
What does it mean? It sounds like the module isn't safe. On the other hand, they say:
This is confusing. Can I help in any way? Please see: Security advisory process and permissions policy
Comment #24
sharma.amitt16 commented@20drei, This module is not covered under security advisory that's why I created an application here for the same. On this thread community is reviewing the module. If they are satisfied with module, they convert the status to RTBC and after that any user with special role can give permission to module author to choose "Security opt in".
Please check security advisory policy for the same.
Comment #25
Anonymous (not verified) commentedI will review and test it as well but I am not a PHP programmer. Hope the module will be covered under security advisory soon.
Thanks @sharma.amitt16
Comment #26
ayalon commentedAutomated Review
https://pareview.sh/node/2574
No warnings found.
Manual Review
Year Only is a small plugin that is using an int field instead of the date field to save the year. It implements a
FieldType, FieldFormatter and a FieldWidget following the Drupal 8 best practices.
Individual user account
[Yes: Follows] the guidelines for individual user accounts.
No duplication
[Yes: Does not cause] module duplication and/or fragmentation.
Master Branch
[Yes: Follows] the guidelines for master branch.
Licensing
[Yes: Follows] the licensing requirements.
3rd party assets/code
[Yes: Follows] the guidelines for 3rd party assets/code.
README.txt/README.md
[Yes: Follows] the guidelines for in-project documentation and/or the README Template.
Code long/complex enough for review
[Yes: Follows] the guidelines for project length and complexity.
Secure code
[No: List of security issues identified.]
Comment #27
sharma.amitt16 commentedThanks ayalon for review.
In your review you have posted
Secure code
[No: List of security issues identified.]
Would you please provide security issues list.
Comment #28
sharma.amitt16 commentedAny update on security opt-in for the module.
Comment #29
visabhishek commentedThanks for your contribution, Amit Sharma !
I updated your account so you can opt into security advisory coverage now.
Here are some recommended readings to help with excellent maintainership:
You can find lots more contributors chatting on IRC in #drupal-contribute. So, come hang out and stay involved!
Thanks, also, for your patience with the review process. Anyone is welcome to participate in the review process. Please consider reviewing other projects that are pending review. I encourage you to learn more about that process and join the group of reviewers.
Thanks to the dedicated reviewer(s) as well.
Comment #30
visabhishek commentedAssigning Credits.
Comment #31
sharma.amitt16 commentedThanks @visabhishek for updating the account.