Skip to content

Fold release and disclosure lessons into the release and security skills - #195

Merged
snoopdave merged 1 commit into
masterfrom
skills-release-disclosure-lessons
Sep 27, 2026
Merged

snoopdave merged 1 commit into
masterfrom
skills-release-disclosure-lessons

Conversation

@snoopdave

Copy link
Copy Markdown
Contributor

Updates the roller-release and roller-security developer skills with procedure changes learned while running the 6.1.6 release and its disclosure. Everything added is generic guidance; no case details.

roller-security

  • Record fix_commit as the commit that landed on the release branch (merge or squash commit), not the PR head, and confirm it is an ancestor of the release tag before citing it.
  • Search the correspondence before stating what a reporter said; log replies when they arrive.
  • New Before READY checklist for CVE records: remove calculator-default or unassessed metrics, don't leave the default status as unaffected unless assessed, check the metadata used in generated emails, and compare saves by content because editors reorder JSON keys.
  • New Publication sequence: READY → send the advisory emails from the portal and confirm each in the list archives → add the vendor-advisory reference → ASF Security sets PUBLIC.
  • New disclosure-notice template for reporters, and sending guidance: send ASF list mail from an @apache.org address, and check drafts made by automation for rewritten links.
  • Pre-disclosure public text (announcements, blog posts, website) stays neutral, and the instructions given to whoever writes it must not reveal what is being withheld.

roller-release

  • Tally binding votes against the ASF roster rather than the website committer list.
  • Send announcements from an @apache.org address and confirm them in the announce@ archive.
  • Promote a candidate with one svn mv commit from a sparse checkout of the repository root; follow redirects when verifying public download URLs, since downloads.apache.org redirects missing files to the archive.
  • Rebase website changes onto the publishing branch, preview with content/ as the web root, and check the rendered HTML (Markdown tables may not be enabled).

Checked with skills/roller-security/scripts/check-private.sh --range origin/master..HEAD (clean). The item template still parses with triage-status.py.

roller-security:
- Record as fix_commit the commit that landed on the release branch, not
  the pull request head, and confirm it is in the release tag.
- Search the correspondence before stating what a reporter said, and log
  replies when they arrive.
- Audit CVE records before READY (stray or default metrics, default
  status, metadata used in generated emails) and document the portal's
  publication sequence.
- Add a disclosure-notice template and guidance for sending ASF list mail.
- Keep pre-disclosure public text neutral, including the instructions
  given to whoever writes it.

roller-release:
- Tally binding votes against the ASF roster, not the website.
- Send announcements from an apache.org address and confirm them in the
  archive.
- Promote in a single svn commit, and follow redirects when verifying
  public download URLs.
- Rebase website changes onto the publishing branch and check the
  rendered HTML before pushing.
@snoopdave
snoopdave merged commit 43f5290 into master Sep 27, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant