[go: up one dir, main page]

Page MenuHomePhabricator

Mstyles (Maryum)
User

Projects (8)

Today

  • Clear sailing ahead.

Tomorrow

  • Clear sailing ahead.

Tuesday

  • Clear sailing ahead.

User Details

User Since
Nov 18 2019, 7:30 PM (253 w, 5 d)
Availability
Available
LDAP User
Mstyles
MediaWiki User
MStyles (WMF) [ Global Accounts ]

Recent Activity

Fri, Sep 27

Mstyles added a comment to T362460: Pentest FY2023/24 - Fundraising Tech.

Testing has been scheduled and there will be a kickoff meeting the week before for any questions

Fri, Sep 27, 1:34 AM · secscrum
Mstyles added a comment to T362459: Pentest FY2023/24 - Kartographer.

Testing has been scheduled and there will be a kickoff meeting the week before for any questions

Fri, Sep 27, 1:34 AM · secscrum
Mstyles updated the task description for T362460: Pentest FY2023/24 - Fundraising Tech.
Fri, Sep 27, 1:33 AM · secscrum
Mstyles updated the task description for T362459: Pentest FY2023/24 - Kartographer.
Fri, Sep 27, 1:33 AM · secscrum

Tue, Sep 24

Mstyles closed T374802: CNA Press Release as Resolved.

confirmed with comms that we are not doing the press release

Tue, Sep 24, 7:22 PM · Security-Team
Mstyles closed T374802: CNA Press Release, a subtask of T364302: Complete the Mitre CNA Partner Process for the Wikimedia Foundation , as Resolved.
Tue, Sep 24, 7:20 PM · Security-Team

Wed, Sep 18

Mstyles updated the task description for T373654: Generate and store credentials for CVE services .
Wed, Sep 18, 5:36 PM · Security-Team

Mon, Sep 16

Mstyles moved T374802: CNA Press Release from Incoming to In Progress on the Security-Team board.
Mon, Sep 16, 6:43 AM · Security-Team
Mstyles created T374802: CNA Press Release.
Mon, Sep 16, 6:43 AM · Security-Team
Mstyles closed T373653: Submit CVE onboarding homework as Resolved.

Confirmed by MITRE

Mon, Sep 16, 6:30 AM · Security-Team
Mstyles closed T373653: Submit CVE onboarding homework, a subtask of T364302: Complete the Mitre CNA Partner Process for the Wikimedia Foundation , as Resolved.
Mon, Sep 16, 6:29 AM · Security-Team

Wed, Sep 11

Mstyles added a comment to T251790: Use Jest in MediaWiki CI to test Vue.js components and plugins.

There's no security review required for Jest at this time as long as it remains a developer dependency. We would like to ensure that the version stays up to date and if there are any critical vulnerabilities found, that you reach out to the security team.

Wed, Sep 11, 7:06 PM · Patch-For-Review, MW-1.43-notes (1.43.0-wmf.23; 2024-09-17), Community-Tech (Island Fox (Sept 9 - 20)), MediaWiki-Core-Tests, Design-Systems-team-20200324-20220422

Tue, Sep 3

Mstyles added a comment to T373654: Generate and store credentials for CVE services .

@Reedy I'll store it in that. I thought there was a shared LastPass for some reason

Tue, Sep 3, 5:05 PM · Security-Team

Sat, Aug 31

Mstyles moved T373726: Create disclosure policy from Incoming to In Progress on the Security-Team board.
Sat, Aug 31, 1:13 AM · Security-Team
Mstyles created T373726: Create disclosure policy.
Sat, Aug 31, 1:13 AM · Security-Team

Fri, Aug 30

Mstyles moved T373654: Generate and store credentials for CVE services from Incoming to In Progress on the Security-Team board.
Fri, Aug 30, 1:03 AM · Security-Team
Mstyles moved T373653: Submit CVE onboarding homework from Incoming to In Progress on the Security-Team board.
Fri, Aug 30, 1:03 AM · Security-Team
Mstyles moved T373652: Update release documentation from Incoming to Waiting on the Security-Team board.
Fri, Aug 30, 1:02 AM · Security-Team
Mstyles created T373654: Generate and store credentials for CVE services .
Fri, Aug 30, 12:51 AM · Security-Team
Mstyles created T373653: Submit CVE onboarding homework.
Fri, Aug 30, 12:49 AM · Security-Team
Mstyles created T373652: Update release documentation.
Fri, Aug 30, 12:41 AM · Security-Team

Aug 28 2024

Mstyles closed T372829: Offboard Hal Triedman from the Security Team as Resolved.
Aug 28 2024, 2:38 AM · Security-Team
Mstyles closed T372829: Offboard Hal Triedman from the Security Team, a subtask of T371644: Requested offboarding-to-volunteer of HTriedman // Transfer ownership of SpinachBot from HTriedman (WMF) to HTriedman, as Resolved.
Aug 28 2024, 2:38 AM · Infrastructure-Foundations, Tools

Aug 27 2024

Mstyles added a comment to T372829: Offboard Hal Triedman from the Security Team.

@sbassett the security landing page has been updated. Only thing left is to remove Hal from the email list, which I will need you to do since I don't have permission.

Aug 27 2024, 8:56 PM · Security-Team
Mstyles updated the task description for T372829: Offboard Hal Triedman from the Security Team.
Aug 27 2024, 8:54 PM · Security-Team
Mstyles updated the task description for T372829: Offboard Hal Triedman from the Security Team.
Aug 27 2024, 6:45 PM · Security-Team
Mstyles updated the task description for T372829: Offboard Hal Triedman from the Security Team.
Aug 27 2024, 6:44 PM · Security-Team
Mstyles added a comment to T372829: Offboard Hal Triedman from the Security Team.

I talked to ITS. They have removed Hal from the Security drive. They are going to merge his current accounts into his contractor accounts after they are provisioned via our Onboarding workflow. If we have any concerns we can let them know. I think that should be fine.

Aug 27 2024, 6:42 PM · Security-Team

Aug 26 2024

Mstyles added a comment to T372829: Offboard Hal Triedman from the Security Team.

I reached out to confirm with ITS, will report back on that. I don't have access to the security-team email list, so I can't remove Hal.

Aug 26 2024, 8:08 PM · Security-Team
Mstyles updated the task description for T372829: Offboard Hal Triedman from the Security Team.
Aug 26 2024, 8:06 PM · Security-Team
Mstyles moved T372767: Offboard Guergana Tzatchkova (WMDE) and Frederik Ring from WMF systems from In Progress to Our Part Is Done on the Security-Team board.
Aug 26 2024, 7:48 PM · Patch-For-Review, Security-Team, Gerrit-Privilege-Requests, SRE-Access-Requests, LDAP-Access-Requests
Mstyles moved T372767: Offboard Guergana Tzatchkova (WMDE) and Frederik Ring from WMF systems from Incoming to In Progress on the Security-Team board.
Aug 26 2024, 7:41 PM · Patch-For-Review, Security-Team, Gerrit-Privilege-Requests, SRE-Access-Requests, LDAP-Access-Requests
Mstyles added a comment to T372767: Offboard Guergana Tzatchkova (WMDE) and Frederik Ring from WMF systems.

@Aklapper perhaps they never had security access to begin with?

Aug 26 2024, 7:40 PM · Patch-For-Review, Security-Team, Gerrit-Privilege-Requests, SRE-Access-Requests, LDAP-Access-Requests
Mstyles added a comment to T372767: Offboard Guergana Tzatchkova (WMDE) and Frederik Ring from WMF systems.

Hey! I'm from the security team and I didn't see either of these folks in acl*security or acl*security_wmde. Perhaps they've already been removed by someone else?

Aug 26 2024, 4:35 PM · Patch-For-Review, Security-Team, Gerrit-Privilege-Requests, SRE-Access-Requests, LDAP-Access-Requests

Aug 19 2024

Mstyles added a comment to T370110: Apache 2.4.61 throws a 403 Forbidden for links containing %3F.

@Aklapper are you okay to resolve this ticket?

Aug 19 2024, 4:12 PM · Vuln-VulnComponent, SecTeam-Processed, collaboration-services, Release-Engineering-Team (Priority Backlog 📥), Wikimedia-Apache-configuration, Phabricator, User-brennen, Security
Mstyles moved T372211: Various XSSes found in Cargo from Incoming to Watching on the Security-Team board.
Aug 19 2024, 4:08 PM · MediaWiki-extensions-Cargo, Vuln-XSS, affects-Miraheze, Security, Security-Team

Aug 15 2024

Mstyles renamed T364302: Complete the Mitre CNA Partner Process for the Wikimedia Foundation from Start the Mitre CNA Partner Process for the Wikimedia Foundation to Complete the Mitre CNA Partner Process for the Wikimedia Foundation .
Aug 15 2024, 11:19 PM · Security-Team
Mstyles added a comment to T364302: Complete the Mitre CNA Partner Process for the Wikimedia Foundation .

No, we still have to do an onboarding and actually become a CNA partner. Unless you think that should be a separate ticket?

Aug 15 2024, 4:53 PM · Security-Team

Aug 13 2024

Mstyles added a comment to T372211: Various XSSes found in Cargo.

@BlankEclair thank you for reporting. I'll follow up with further information soon

Aug 13 2024, 4:07 PM · MediaWiki-extensions-Cargo, Vuln-XSS, affects-Miraheze, Security, Security-Team
Mstyles added a comment to T364302: Complete the Mitre CNA Partner Process for the Wikimedia Foundation .

Met with Mitre and the finalized scope is:

Aug 13 2024, 3:52 PM · Security-Team

Jul 22 2024

Mstyles changed the visibility for T370022: Version `4.3.5` of `smarty/smarty` library in Extension:Widgets library has CVE-2024-35226.
Jul 22 2024, 4:56 PM · SecTeam-Processed, Vuln-VulnComponent, Patch-For-Review, MediaWiki-extensions-Widgets, Security, Security-Team
Mstyles moved T370022: Version `4.3.5` of `smarty/smarty` library in Extension:Widgets library has CVE-2024-35226 from In Progress to Our Part Is Done on the Security-Team board.
Jul 22 2024, 4:56 PM · SecTeam-Processed, Vuln-VulnComponent, Patch-For-Review, MediaWiki-extensions-Widgets, Security, Security-Team
Mstyles added a comment to T370110: Apache 2.4.61 throws a 403 Forbidden for links containing %3F.

@Aklapper since the gerrit patch is public this ticket is okay to be public as well. I went ahead and changed the policy

Jul 22 2024, 4:35 PM · Vuln-VulnComponent, SecTeam-Processed, collaboration-services, Release-Engineering-Team (Priority Backlog 📥), Wikimedia-Apache-configuration, Phabricator, User-brennen, Security
Mstyles changed the visibility for T370110: Apache 2.4.61 throws a 403 Forbidden for links containing %3F.
Jul 22 2024, 4:33 PM · Vuln-VulnComponent, SecTeam-Processed, collaboration-services, Release-Engineering-Team (Priority Backlog 📥), Wikimedia-Apache-configuration, Phabricator, User-brennen, Security

Jul 19 2024

Mstyles added a comment to T364302: Complete the Mitre CNA Partner Process for the Wikimedia Foundation .

@sbassett once it's scheduled you'll receive an invite

Jul 19 2024, 9:26 PM · Security-Team

Jul 18 2024

Mstyles added a comment to T364302: Complete the Mitre CNA Partner Process for the Wikimedia Foundation .

This scope still did not pass inspection by Mitre, so we are having a meeting next week to discuss more in detail. Anyone who is interested in coming to the meeting let me know.

Jul 18 2024, 6:30 PM · Security-Team

Jul 17 2024

Mstyles updated subscribers of T369945: Epic: Deploy Chart extension on beta cluster.

@sbassett is out this week, so I will set up a meeting next week so we can discuss the beta deployment

Jul 17 2024, 1:23 AM · Epic, SecTeam-Processed, Security-Team, Wikimedia-extension-review-queue, Wikimedia-Extension-setup, Charts

Jul 15 2024

Mstyles added a project to T370022: Version `4.3.5` of `smarty/smarty` library in Extension:Widgets library has CVE-2024-35226: Patch-For-Review.

This patch looks good but I would like someone familiar with this extension to review it as well.

Jul 15 2024, 4:39 PM · SecTeam-Processed, Vuln-VulnComponent, Patch-For-Review, MediaWiki-extensions-Widgets, Security, Security-Team

Jun 17 2024

Mstyles added a comment to T364302: Complete the Mitre CNA Partner Process for the Wikimedia Foundation .

Great, I think this is the final scope: "Any code repository hosted under gerrit.wikimedia.org, gitlab.wikimedia.org or github.com/wikimedia that is not archived or a fork of an upstream project or otherwise unmaintained by the WMF or Wikimedia Community"

Jun 17 2024, 4:53 PM · Security-Team

Jun 14 2024

Mstyles added a comment to T364302: Complete the Mitre CNA Partner Process for the Wikimedia Foundation .

I like that, but I do think that we might either have to remove active or define what that means. Do we mean active in the last 6 months? Last year?

Jun 14 2024, 9:54 PM · Security-Team
Mstyles added a comment to T364302: Complete the Mitre CNA Partner Process for the Wikimedia Foundation .

There needs to be clarity on what projects we will manage or not. Originally when we started this project we did say Mediawiki core, skins, and extensions, but if you want to open it up that's fine with me. I'm fine to say vulnerabilities in software maintained by the Wikimedia Foundation or something like that.

Jun 14 2024, 4:53 PM · Security-Team
Mstyles added a comment to T364302: Complete the Mitre CNA Partner Process for the Wikimedia Foundation .

It can't be a minimal list, it needs to be an exact list of what we will issue CVEs for. I'm only saying this because I met with Mitre, and they want a canonical list of what we will and will not cover. We can also say something like, "Scope The GitLab application, any project hosted on GitLab.com in a public repository, and any vulnerabilities discovered by GitLab that are not in another CNA’s scope" but then that might be more broad than we want. Go has one that says, "Vulnerabilities in software published by the Go Project (including the Go standard library, Go toolchain, and the golang.org modules) and publicly disclosed vulnerabilities in publicly importable packages in the Go ecosystem, unless covered by another CNA’s scope". So we could say something very similar to that.

Jun 14 2024, 4:52 PM · Security-Team
Mstyles added a comment to T364302: Complete the Mitre CNA Partner Process for the Wikimedia Foundation .

How about

Jun 14 2024, 4:43 PM · Security-Team

Jun 13 2024

Mstyles added a comment to T364302: Complete the Mitre CNA Partner Process for the Wikimedia Foundation .

I met with Mitre today and there are two issues to address before we can have the official onboarding meeting with the whole team.
They wanted to get very clear on the scope and we need to have a proper advisory page.

Jun 13 2024, 11:54 PM · Security-Team

Jun 10 2024

Mstyles closed T366983: Github MathJax unicode xss exploit as Resolved.

@Physikerwelt thank you for reporting this. This issue looks like it's referring to CVE-2023-39663 which only affects versions of Mathjax under and including 2.7.9. The current version of Mathjax for WMF production is 3.2.2 so WMF systems are not affected. I'm marking this as resolved, but if you have any other questions or comments, please let us know.

Jun 10 2024, 9:22 PM · Vuln-XSS, Math, Mathoid, Security, Security-Team
Mstyles added a comment to T364302: Complete the Mitre CNA Partner Process for the Wikimedia Foundation .

legal approved terms of service in coupa. I'm meeting with Mitre this week to talk about our scope and advisory page. There might need to be some udpates. More to come

Jun 10 2024, 4:16 PM · Security-Team

Jun 5 2024

Mstyles closed T366493: Offboard Kelton Hurd from Security Team as Resolved.
Jun 5 2024, 10:38 PM · SecTeam-Processed, Security-Team
Mstyles updated the task description for T366493: Offboard Kelton Hurd from Security Team.
Jun 5 2024, 10:38 PM · SecTeam-Processed, Security-Team
Mstyles updated the task description for T366493: Offboard Kelton Hurd from Security Team.
Jun 5 2024, 10:36 PM · SecTeam-Processed, Security-Team
Mstyles updated the task description for T366493: Offboard Kelton Hurd from Security Team.
Jun 5 2024, 10:36 PM · SecTeam-Processed, Security-Team

Jun 4 2024

Mstyles updated the task description for T366493: Offboard Kelton Hurd from Security Team.
Jun 4 2024, 7:47 PM · SecTeam-Processed, Security-Team
Mstyles updated the task description for T366493: Offboard Kelton Hurd from Security Team.
Jun 4 2024, 5:50 PM · SecTeam-Processed, Security-Team

Jun 3 2024

Mstyles added a comment to T364302: Complete the Mitre CNA Partner Process for the Wikimedia Foundation .

@acooper I filled out a coupa request with legal

Jun 3 2024, 9:35 PM · Security-Team

May 31 2024

Mstyles added a comment to T364302: Complete the Mitre CNA Partner Process for the Wikimedia Foundation .

Mitre responded on May 15, but I was OOO so I filled out the CNA registration form today. I did reach out to legal about the terms of service as well. The next steps are for Mitre to schedule a meeting to discuss the program more. If anyone is interested in the onboarding materials, there is information about the onboarding process and the CNA Rules.

May 31 2024, 2:09 AM · Security-Team

May 30 2024

Mstyles added projects to T366302: Supply Chain Attack Threat Model: Application Security Reviews, Security.
May 30 2024, 4:17 PM · Security, Application Security Reviews, secscrum
Mstyles created T366302: Supply Chain Attack Threat Model.
May 30 2024, 4:17 PM · Security, Application Security Reviews, secscrum

May 16 2024

Mstyles closed T361690: Application Security Review Request : AutoModerator as Resolved.

Security Review Summary - T361690 - 2024-15-05
Last commit reviewed: 54d3a6d

May 16 2024, 7:02 AM · Moderator-Tools-Team, Automoderator, secscrum, Security, Application Security Reviews
Mstyles closed T361690: Application Security Review Request : AutoModerator, a subtask of T361643: Deploy the AutoModerator extension to production (testwiki only), as Resolved.
May 16 2024, 7:01 AM · Moderator-Tools-Team, Automoderator, Wikimedia-extension-review-queue, Wikimedia-Extension-setup

May 15 2024

Mstyles created P62428 Semgrep custom rules.
May 15 2024, 9:31 PM

May 9 2024

Mstyles moved T364560: Update golang gosec security template to use go 1.22 from Incoming to In Progress on the Security-Team board.
May 9 2024, 4:25 PM · SecTeam-Processed, Security-Team, Security, GitLab-Application-Security-Pipeline
Mstyles created T364560: Update golang gosec security template to use go 1.22.
May 9 2024, 4:25 PM · SecTeam-Processed, Security-Team, Security, GitLab-Application-Security-Pipeline

May 7 2024

Mstyles added a comment to T361690: Application Security Review Request : AutoModerator.

@jsn.sherman I'll aim for the end of May for this review, but in case I'm not able to post it, you can go ahead and get the pilot rolling

May 7 2024, 9:58 AM · Moderator-Tools-Team, Automoderator, secscrum, Security, Application Security Reviews

May 6 2024

sbassett awarded T364302: Complete the Mitre CNA Partner Process for the Wikimedia Foundation a Like token.
May 6 2024, 4:21 PM · Security-Team
sbassett awarded T353904: Write and send supplementary release announcement for extensions and skins with security patches (1.39.7/1.40.3/1.41.1) a Like token.
May 6 2024, 4:19 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
Mstyles created T364302: Complete the Mitre CNA Partner Process for the Wikimedia Foundation .
May 6 2024, 10:15 AM · Security-Team
Mstyles added a comment to T361690: Application Security Review Request : AutoModerator.

@jsn.sherman thank for letting me know, is there a deadline that I should know about for the review? If not, I will post mid June.

May 6 2024, 10:07 AM · Moderator-Tools-Team, Automoderator, secscrum, Security, Application Security Reviews
Mstyles changed the visibility for T353904: Write and send supplementary release announcement for extensions and skins with security patches (1.39.7/1.40.3/1.41.1).
May 6 2024, 10:01 AM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
Mstyles closed T353904: Write and send supplementary release announcement for extensions and skins with security patches (1.39.7/1.40.3/1.41.1) as Resolved.

Supplemental announcement is out!

May 6 2024, 10:01 AM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
Mstyles closed T353904: Write and send supplementary release announcement for extensions and skins with security patches (1.39.7/1.40.3/1.41.1), a subtask of T353894: Release MediaWiki 1.39.7/1.40.3/1.41.1, as Resolved.
May 6 2024, 10:01 AM · MediaWiki-Releasing, Security
Mstyles added a comment to T353904: Write and send supplementary release announcement for extensions and skins with security patches (1.39.7/1.40.3/1.41.1).

Subject: MediaWiki Extensions and Skins Security Release Supplement (1.39.7/1.40.3/1.41.1)

May 6 2024, 9:53 AM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
Mstyles updated the task description for T353904: Write and send supplementary release announcement for extensions and skins with security patches (1.39.7/1.40.3/1.41.1).
May 6 2024, 9:13 AM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
Mstyles renamed T356190: CVE-2024-34503: ReportIncident REST API does not use a CSRF token from CVE-2024-34501: ReportIncident REST API does not use a CSRF token to CVE-2024-34503: ReportIncident REST API does not use a CSRF token.
May 6 2024, 9:12 AM · MW-1.42-notes (1.42.0-wmf.17; 2024-02-06), Trust and Safety Product Sprint (Sprint Kazoo (Jan 29 - Feb 9 2024)), Trust and Safety Product Team, Incident-Reporting-System, Security, Security-Team
Mstyles renamed T355434: CVE-2024-34505: Temporary account IP reveal does not check the deleted status of the performer before revealing the IP address associated with an edit/log event from Temporary account IP reveal does not check the deleted status of the performer before revealing the IP address associated with an edit/log event to CVE-2024-34505: Temporary account IP reveal does not check the deleted status of the performer before revealing the IP address associated with an edit/log event.
May 6 2024, 9:09 AM · MW-1.42-notes (1.42.0-wmf.17; 2024-02-06), Trust and Safety Product Sprint (Sprint Kazoo (Jan 29 - Feb 9 2024)), SecTeam-Processed, Temporary accounts, CheckUser, Trust and Safety Product Team, Security
Mstyles renamed T356183: CVE-2024-34504: IPInfo REST APIs are not safe from CSRF attacks from IPInfo REST APIs are not safe from CSRF attacks to CVE-2024-34504: IPInfo REST APIs are not safe from CSRF attacks.
May 6 2024, 9:08 AM · Trust and Safety Product Sprint (Sprint Piano (Feb 19th - 1st March)), MW-1.42-notes (1.42.0-wmf.19; 2024-02-20), Patch-For-Review, Vuln-CSRF, SecTeam-Processed, IP Info, Trust and Safety Product Team, Security, Security-Team
Mstyles renamed T357101: CVE-2024-34502: Special:MergeLexemes makes edits on GET requests without edit tokens from Special:MergeLexemes makes edits on GET requests without edit tokens to CVE-2024-34502: Special:MergeLexemes makes edits on GET requests without edit tokens.
May 6 2024, 9:02 AM · MW-1.42-notes (1.42.0-wmf.23; 2024-03-19), Vuln-CSRF, SecTeam-Processed, Wikidata Dev Team (Wikidata.org Slice), Wikidata Lexicographical data, Wikidata, Security, Security-Team
Mstyles renamed T356190: CVE-2024-34503: ReportIncident REST API does not use a CSRF token from ReportIncident REST API does not use a CSRF token to CVE-2024-34501: ReportIncident REST API does not use a CSRF token.
May 6 2024, 9:00 AM · MW-1.42-notes (1.42.0-wmf.17; 2024-02-06), Trust and Safety Product Sprint (Sprint Kazoo (Jan 29 - Feb 9 2024)), Trust and Safety Product Team, Incident-Reporting-System, Security, Security-Team
Mstyles renamed T357203: CVE-2024-34500: XSS through interface message in UnlinkedWikibase from XSS through interface message in UnlinkedWikibase to CVE-2024-34500: XSS through interface message in UnlinkedWikibase.
May 6 2024, 8:57 AM · Vuln-XSS, SecTeam-Processed, MediaWiki-extensions-UnlinkedWikibase, affects-Miraheze, Security, Security-Team

Apr 23 2024

Mstyles added a comment to T362588: CVE-2024-40601: Classic CSRF in MediaWikiChat's API modules.

@ashley Since MediaWikiChat is not deployed in WMF production, this patch can be pushed through github.

Apr 23 2024, 3:18 PM · security-bug, SecTeam-Processed, Vuln-CSRF, MediaWikiChat, Security
Mstyles closed T363068: Please remove 2FA from Vito Genovese Wikimedia SUL account as Declined.
Apr 23 2024, 3:18 PM · SecTeam-Processed, Trust-and-Safety, Security
Mstyles changed the visibility for T363068: Please remove 2FA from Vito Genovese Wikimedia SUL account.
Apr 23 2024, 3:16 PM · SecTeam-Processed, Trust-and-Safety, Security

Apr 15 2024

Mstyles closed T362199: Security Issue Access Request for jrbranaa as Resolved.

security issue access has been granted

Apr 15 2024, 5:32 PM · SecTeam-Processed, Security-Team, Security
Mstyles added a member for acl*security_management: Jrbranaa.
Apr 15 2024, 5:29 PM

Apr 13 2024

Mstyles created T362460: Pentest FY2023/24 - Fundraising Tech.
Apr 13 2024, 12:20 AM · secscrum
Mstyles created T362459: Pentest FY2023/24 - Kartographer.
Apr 13 2024, 12:17 AM · secscrum

Apr 10 2024

Mstyles reassigned T360070: Application Security Review Request : Extension:IPReputation from Mstyles to sbassett.
Apr 10 2024, 4:34 PM · user-sbassett, MediaWiki-extensions-IPReputation, secscrum, Security, Application Security Reviews

Apr 8 2024

Mstyles added a comment to T361690: Application Security Review Request : AutoModerator.

@Samwalton9-WMF this review will be scoped to the extension only, the models will be out of scope for this review. Is it possible that this tool will replace existing auto moderator tools? For the timeline, does that mean the review can start in May? We're planning to do this review this quarter.

Apr 8 2024, 6:27 PM · Moderator-Tools-Team, Automoderator, secscrum, Security, Application Security Reviews

Apr 5 2024

Mstyles added a comment to T361943: Decide on a Software Bill of Materials (SBOM) format for MediaWiki.

It looks like it's not too bad to convert from CycloneDX to SPDX, so even if we decide to go with CycloneDX we can still get the SPDX data if we want it. CycloneDX seems to have more tooling and also provides a license scanner to look at the licenses @Jdforrester-WMF was referencing.

Apr 5 2024, 6:30 PM · SecTeam-Processed, Security-Team, Security

Apr 2 2024

Mstyles moved T361260: Add limits to loop condition from Incoming to Watching on the Security-Team board.
Apr 2 2024, 5:48 PM · MW-1.43-notes (1.43.0-wmf.1; 2024-04-16), Security-Team, Security, function-schemata, Abstract Wikipedia Fix-It tasks, Abstract Wikipedia team
Mstyles added a project to T361260: Add limits to loop condition: Security-Team.
Apr 2 2024, 5:48 PM · MW-1.43-notes (1.43.0-wmf.1; 2024-04-16), Security-Team, Security, function-schemata, Abstract Wikipedia Fix-It tasks, Abstract Wikipedia team
Mstyles edited projects for T361260: Add limits to loop condition, added: Security; removed secscrum.
Apr 2 2024, 5:47 PM · MW-1.43-notes (1.43.0-wmf.1; 2024-04-16), Security-Team, Security, function-schemata, Abstract Wikipedia Fix-It tasks, Abstract Wikipedia team