Security/Archived/Radar: Difference between revisions

From MozillaWiki
Jump to navigation Jump to search
m (Amuntner moved page Security/Radar to Security/Archived/Radar: Out of date page, no longer used. Archiving for historical purposes.)
 
(42 intermediate revisions by 2 users not shown)
Line 1: Line 1:
Tracking of features / patches needing security review
__NOTOC__
{| class="wikitable collapsible collapsed"
! [https://bugzil.la/UNCONFIRMED%2CNEW%2CREOPENED%2Bproduct%3A%22mozilla.org%22%2Bcomponent%3A%22Security%20Assurance%3A%20Review%20Request%22%2Bsw%3A%22%5Bpending%20secreview%5D%22%2B-sw%3A%22%5Btriage%22 sec-review-needed & unscheduled]
|-
|<bugzilla>
{
"product": "mozilla.org",
"component": "Security Assurance: Review Request",
"quicksearch": "status:new,assigned,reopened,unconfirmed",
"whiteboard": "[pending secreview]",
"whiteboard_type": "contains",
"whiteboar": "[triage",
"whiteboar_type": "not_contains"
}
</bugzilla>
|}
 
{| class="wikitable collapsible"
! Review Stats
|-
! Open Reviews
|-
|<bugzilla type="count" display="bar">
    {
        "product": "mozilla.org",
"component": "Security Assurance: Review Request",
"quicksearch": "status:new,assigned,reopened,unconfirmed",
"whiteboard": "[triage",
"whiteboard_type": "not_contains",
"whiteboard": "[needs info]",
"whiteboard_type": "not_contains",
        "x_axis_field": "status"
    }</bugzilla>
|-
! Completed Reviews Q1:2013
|-
|<bugzilla type="count" display="bar">
    {
        "component": "Security Assurance: Review Request",
        "changed_after": "2012-12-31",
        "changed_before": "2013-03-31",
        "changed_field": "status",
        "changed_field_to": "resolved",
        "x_axis_field": "status"
    }
</bugzilla>
|-
|<bugzilla type="count" display="bar">
    {
        "component": "Security Assurance: Review Request",
        "changed_after": "2012-12-31",
        "changed_before": "2013-03-31",
        "changed_field": "status",
        "changed_field_to": "resolved",
        "x_axis_field": "assigned_to"
    }
</bugzilla>
|-
|}


{{ForceRefreshButton}}
{| class="wikitable collapsible collapsed"
|-
! Completed Reviews Prior Quarters
|-
!Completed Reviews Q4:2012
|-
|<bugzilla type="count" display="bar">
    {
        "component": "Security Assurance: Review Request",
        "changed_after": "2012-09-30",
        "changed_before": "2012-12-30",
        "changed_field": "status",
        "changed_field_to": "resolved",
        "x_axis_field": "status"
    }
</bugzilla>
|-
|<bugzilla type="count" display="bar">
    {
        "component": "Security Assurance: Review Request",
        "changed_after": "2012-09-30",
        "changed_before": "2012-12-30",
        "changed_field": "status",
        "changed_field_to": "resolved",
        "x_axis_field": "assigned_to"
    }
</bugzilla>
|-
! Completed Reviews Q3:2012
|-
|<bugzilla type="count" display="bar">
    {
        "component": "Security Assurance: Review Request",
        "changed_after": "2012-07-01",
        "changed_before": "2012-09-30",
        "changed_field": "status",
        "changed_field_to": "resolved",
        "x_axis_field": "status"
    }</bugzilla>
|-
|<bugzilla type="count" display="bar">
    {
        "component": "Security Assurance: Review Request",
        "changed_after": "2012-07-01",
        "changed_before": "2012-09-30",
        "changed_field": "status",
        "changed_field_to": "resolved",
        "x_axis_field": "assigned_to"
    }</bugzilla>
|-
! Completed Reviews Q2:2012
|-
|<bugzilla type="count" display="bar">
    {
        "component": "Security Assurance: Review Request",
"changed_after": "2012-03-31",
        "changed_before": "2012-06-01",
"changed_field": "status",
        "changed_field_to": "resolved",
        "x_axis_field": "status"
    }</bugzilla>
|-
|<bugzilla type="count" display="bar">
    {
        "component": "Security Assurance: Review Request",
"changed_after": "2012-03-31",
        "changed_before": "2012-06-01",
"changed_field": "status",
        "changed_field_to": "resolved",
        "x_axis_field": "assigned_to"
    }</bugzilla>
|-
|}


== Review Active ==
* Security reviews are on-going
<table class="querytable sortable">
<tr>
<td class="header" style="width: 25%;">Feature</td>
<td class="header" style="width: 5%;">Feature List</td>
<td class="header" style="width: 10%;">Target Rel</td>
<td class="header" style="width: 13%;">Prod Mgr</td>
<td class="header" style="width: 13%;">Lead Engr</td>
<td class="header" style="width: 13%;">Security lead</td>
<td class="header" style="width: 10%;">Security status</td>
<td class="header unsortable" style="width: 15%;">Security notes</td>
<td class="header" style="width: 15%;">Last Modified</td>
</tr>
{{#ask: [[Category:Feature Page]] [[Feature security status::sec-review-active]] [[Feature security health::!Assigned]]
| ?#
| ?Feature name#
| ?Feature list#
| ?Feature version#
| ?Feature product manager#
| ?Feature lead engineer#
| ?Feature security lead#
| ?Feature security status#
| ?Feature security notes#
| ?Modification date#
| ?Feature security health#
| mainlabel=-
| sort=Feature priority,Feature stage
| format=template
| template=SecurityRadarListTable
}}
</table>


== Review Active & Assigned ==
{{ForceRefreshButton}}
<table class="querytable sortable">
<tr>
<td class="header" style="width: 25%;">Feature</td>
<td class="header" style="width: 5%;">Feature List</td>
<td class="header" style="width: 10%;">Target Rel</td>
<td class="header" style="width: 13%;">Prod Mgr</td>
<td class="header" style="width: 13%;">Lead Engr</td>
<td class="header" style="width: 13%;">Security lead</td>
<td class="header" style="width: 10%;">Security status</td>
<td class="header unsortable" style="width: 15%;">Security notes</td>
<td class="header" style="width: 15%;">Last Modified</td>
</tr>
{{#ask: [[Category:Feature Page]] [[Feature security status::sec-review-active]] [[Feature security health::Assigned]]
| ?#
| ?Feature name#
| ?Feature list#
| ?Feature version#
| ?Feature product manager#
| ?Feature lead engineer#
| ?Feature security lead#
| ?Feature security status#
| ?Feature security notes#
| ?Modification date#
| ?Feature security health#
| mainlabel=-
| sort=Feature priority,Feature stage
| format=template
| template=SecurityRadarListTable
}}
</table>
== Review Needed ==
* triaged to need review, review unscheduled


<table class="querytable sortable">
{| class="wikitable collapsible collapsed"
! SecReview Open Action Items
|-
|<table class="querytable sortable">
<tr>
<tr>
<td class="header" style="width: 25%;">Feature</td>
<td class="header" style="width: 10%;">SecReview Name</td>
<td class="header" style="width: 5%;">Feature List</td>
<td class="header" style="width: 5%;">Action Item Status</td>
<td class="header" style="width: 10%;">Target Rel</td>
<td class="header" style="width: 5%;">Target Rel</td>
<td class="header" style="width: 13%;">Prod Mgr</td>
<td class="header" style="width: 25%;">Action Items</td>
<td class="header" style="width: 13%;">Lead Engr</td>
<td class="header" style="width: 13%;">Security lead</td>
<td class="header" style="width: 10%;">Security status</td>
<td class="header" style="width: 15%;">Security notes</td>
<td class="header" style="width: 15%;">Last Modified</td>
</tr>
</tr>
{{#ask: [[Category:Feature Page]] [[Feature security status::sec-review-needed]] [[Feature security health::!Assigned]]
{{#ask: [[Category:SecReview]] [[SecReview action item status::In Progress]]
| ?#
| ?#
| ?Feature name#
| ?SecReview name#
| ?Feature list#
| ?SecReview action item status#
| ?Feature version#
| ?Feature version#
| ?Feature product manager#
| ?SecReview action items#
| ?Feature lead engineer#
| ?Feature security lead#
| ?Feature security status#
| ?Feature security notes#
| ?Modification date#
| ?Feature security health#  
| mainlabel=-
| mainlabel=-
| sort=Feature version,Feature priority,Feature stage
| format=template
| format=template
| template=SecurityRadarListTable
| template=SecReviewActionTable}}
}}
</table>
</table>
|}
== Bugs that need more information==
*[https://bugzil.la/comp%3A%22Security%20Assurance%3A%20Review%20Request%22%20sw%3A%22%5Bneeds%20info%22 Needs Info]
**Status: REOPENED, NEW, ASSIGNED, UNCONFIRMED
**Component: Security Assurance: Review Request
**Product: mozilla.org
**Whiteboard: [needs info]


== Review Needed (Assigned)==
==Marking Queries==
* triaged to need review, assigned to a resource
*[https://bugzil.la/comp%3A%22security%20assurance%3A%20review%20request%22%20-sw%3A%22%5Bneeds%20info%5D%22%20-sw%3A%22%5Bscore%3A%22 Risk Undetermined]
**Status: UNCONFIRMED, NEW, ASSIGNED, REOPENED
**Component: Security Assurance: Review Request
**Whiteboard: (does not contain the string) [score:
**Whiteboard: (does not contain the string) [needs info]
* Query below searches for bugs that are owned by the person running the query
**[https://bugzil.la/comp%3A%22Security%20Assurance%3A%20Review%20Request%22%20-sw%3A%22%5Bneeds%20info%5D%22%20-sw%3A%22%5Bscore%3A%22%20owner:%25user%25 Your Bugs]


<table class="querytable sortable">
*[https://bugzilla.mozilla.org/buglist.cgi?field0-0-0=cf_due_date;query_format=advanced;resolution=---;type0-0-0=isempty;component=Security%20Assurance%3A%20Review%20Request;product=mozilla.org Due Date Undetermined]
<tr>
**Status: UNCONFIRMED, NEW, ASSIGNED, REOPENED
<td class="header" style="width: 25%;">Feature</td>
**Component: Security Assurance: Review Request
<td class="header" style="width: 5%;">Feature List</td>
**Product: mozilla.org
<td class="header" style="width: 10%;">Target Rel</td>
**Due Date: (is empty)
<td class="header" style="width: 13%;">Prod Mgr</td>
**Whiteboard: (does not contain the string) [needs info]
<td class="header" style="width: 13%;">Lead Engr</td>
* Query below searches for bugs that are owned by the person running the query
<td class="header" style="width: 13%;">Security lead</td>
**[https://bugzilla.mozilla.org/buglist.cgi?field0-0-0=cf_due_date;query_format=advanced;resolution=---;type0-0-0=isempty;component=Security%20Assurance%3A%20Review%20Request;product=mozilla.org;field1-0-0=assigned_to;type1-0-0=equals;value1-0-0=%25user%25 Your Bugs]
<td class="header" style="width: 10%;">Security status</td>
<td class="header" style="width: 15%;">Security notes</td>
<td class="header" style="width: 15%;">Last Modified</td>
</tr>
{{#ask: [[Category:Feature Page]] [[Feature security status::sec-review-needed]] [[Feature security health::Assigned]]
| ?#
| ?Feature name#
| ?Feature list#
| ?Feature version#
| ?Feature product manager#
| ?Feature lead engineer#
| ?Feature security lead#
| ?Feature security status#
| ?Feature security notes#
| ?Modification date#
| ?Feature security health#
| mainlabel=-
| sort=Feature version,Feature priority,Feature stage
| format=template
| template=SecurityRadarListTable
}}
</table>


== Review Scheduled ==
* A review is scheduled
<table class="querytable sortable">
<tr>
<td class="header" style="width: 25%;">Feature</td>
<td class="header" style="width: 5%;">Feature List</td>
<td class="header" style="width: 10%;">Target Rel</td>
<td class="header" style="width: 13%;">Prod Mgr</td>
<td class="header" style="width: 13%;">Lead Engr</td>
<td class="header" style="width: 13%;">Security lead</td>
<td class="header" style="width: 10%;">Security status</td>
<td class="header unsortable" style="width: 15%;">Security notes</td>
<td class="header" style="width: 15%;">Last Modified</td>
</tr>
{{#ask: [[Category:Feature Page]] [[Feature security status::sec-review-sched]]
| ?#
| ?Feature name#
| ?Feature list#
| ?Feature version#
| ?Feature product manager#
| ?Feature lead engineer#
| ?Feature security lead#
| ?Feature security status#
| ?Feature security notes#
| ?Modification date#
| ?Feature security health#
| mainlabel=-
| sort=Feature priority,Feature stage
| format=template
| template=SecurityRadarListTable
}}
</table>
== Triage Needed==
== Triage Needed==
*[[Security/Radar/Triage|Triage]]
*[[Security/Radar/Triage|Triage]]
Line 173: Line 188:
*[[Security/Radar/complete|complete]]
*[[Security/Radar/complete|complete]]
*[[Security/Radar/pass| sec-review-unnecessary]]
*[[Security/Radar/pass| sec-review-unnecessary]]
'' Bugzilla''
* [https://bugzil.la/ALL+!sec-review-complete Sec-Review-Complete]
** Keyword: sec-review-complete
== Legend  ==
{| class="fullwidth-table"
|-
| {{StatusHealthy|status=&nbsp;}}
| Healthy: things are on track
|-
| {{StatusAtRisk|status=&nbsp;}}
| At Risk: completion of tasks on time is at risk.
|-
| {{StatusBlocked|status=&nbsp;}}
| Blocked: security concern is blocking
|-
| {{StatusAssigned|status=&nbsp;}}
| Assignd: being worked by someone else.
|-
| '''ETA'''
| Estimated date for completion of the current feature task. Overall ETA for the feature is the product release date.
|}
== Old Radar Pages ==
*[[Security/Radar/Active|Active]]
*[[Security/Radar/Triage|Triage]]
*[[Security/Radar/OffScope|Off Scope]]

Latest revision as of 19:24, 25 April 2016

Review Stats
Open Reviews

Bugzilla query error

Invalid type (count) and display (table) combination1

Completed Reviews Q1:2013

Bugzilla query error

Invalid type (count) and display (table) combination1

Bugzilla query error

Invalid type (count) and display (table) combination1


Bugs that need more information

  • Needs Info
    • Status: REOPENED, NEW, ASSIGNED, UNCONFIRMED
    • Component: Security Assurance: Review Request
    • Product: mozilla.org
    • Whiteboard: [needs info]

Marking Queries

  • Risk Undetermined
    • Status: UNCONFIRMED, NEW, ASSIGNED, REOPENED
    • Component: Security Assurance: Review Request
    • Whiteboard: (does not contain the string) [score:
    • Whiteboard: (does not contain the string) [needs info]
  • Query below searches for bugs that are owned by the person running the query
  • Due Date Undetermined
    • Status: UNCONFIRMED, NEW, ASSIGNED, REOPENED
    • Component: Security Assurance: Review Request
    • Product: mozilla.org
    • Due Date: (is empty)
    • Whiteboard: (does not contain the string) [needs info]
  • Query below searches for bugs that are owned by the person running the query

Triage Needed

Completed Work