Security/Firefox/Security Bug Triage Process: Difference between revisions

updating buglinks to account for "stalled" counts
(Update Assumptions)
(updating buglinks to account for "stalled" counts)
 
Line 15: Line 15:
#*# needinfo the assignee
#*# needinfo the assignee
#* If the bug is an enhancement, set keyword to sec-want and no owner is needed to be assigned.
#* If the bug is an enhancement, set keyword to sec-want and no owner is needed to be assigned.
#* [https://bugzil.la/class%3Aclient%2Ccomp%20kw:sec-high%2Csec-critical%20%40nobody&order=Last+Changed '''Unassigned''' sec-high and sec-critical bugs]
#* [https://bugzil.la/class%3Aclient%2Ccomp%20kw:sec-high%2Csec-critical%20-kw:stalled%20%40nobody&order=Last+Changed '''Unassigned''' sec-high and sec-critical bugs] ([https://bugzil.la/class%3Aclient%2Ccomp%20kw:sec-high%2Csec-critical%20%40nobody&order=Last+Changed including "stalled"])
#* [https://bugzil.la/class%3Aclient%2Ccomp%20kw:sec-high%2Csec-critical&order=Last+Changed All sec-high and sec-critical bugs]
#* [https://bugzil.la/class%3Aclient%2Ccomp%20kw:sec-high%2Csec-critical%20-kw:stalled&order=Last+Changed All sec-high and sec-critical bugs] ([https://bugzil.la/class%3Aclient%2Ccomp%20kw:sec-high%2Csec-critical&order=Last+Changed including "Stalled"])
# The assigned bug owner needs to review and determine the next step within 3 business days.  
# The assigned bug owner needs to review and determine the next step within 3 business days.  
#* The next step should be documented with the ETA of the patch in the bug.  
#* The next step should be documented with the ETA of the patch in the bug.  
#* If the assigned bug is not updated with next steps by the assignee within 3 business days, the assignee’s manager will be needinfo.
#* If the assigned bug is not updated with next steps by the assignee within 3 business days, the assignee’s manager will be needinfo.
#* Sec-critical bugs should be fixed within two weeks. [[https://bugzil.la/class%3Aclient%2Ccomp%20kw:sec-critical%20creation_ts%3C2w Older sec-critical bugs]]
#* Sec-critical bugs should be fixed within two weeks. [https://bugzil.la/class%3Aclient%2Ccomp%20kw:sec-critical%20-kw:stalled%20creation_ts%3C2w Older sec-critical bugs] ([https://bugzil.la/class%3Aclient%2Ccomp%20kw:sec-critical%20creation_ts%3C2w including "stalled"])
#* Sec-high bugs should be fixed within 6 weeks. [[https://bugzil.la/class%3Aclient%2Ccomp%20kw:sec-high%20creation_ts%3C6w Older sec-high bugs]]
#* Sec-high bugs should be fixed within 6 weeks. [https://bugzil.la/class%3Aclient%2Ccomp%20kw:sec-high%20-kw:stalled%20creation_ts%3C6w Older sec-high bugs] ([https://bugzil.la/class%3Aclient%2Ccomp%20kw:sec-high%20creation_ts%3C6w including "stalled"])
#* If it is not possible to be fixed within those timeframes, the assignee needs to
#* If it is not possible to be fixed within those timeframes, the assignee needs to
#*# Get sign off from both the Senior Engineering Manager of Firefox Security and from the relevant engineering director, who agree on an alternative timeframe or resolution.
#*# Get sign off from both the Senior Engineering Manager of Firefox Security and from the relevant engineering director, who agree on an alternative timeframe or resolution.
#*# Where security engineering and engineering directors do not sign off or cannot agree on an alternative timeframe, the decision on bug will follow the [[Security/Firefox/Security_Bug_Escalation_Process|Security_Bug_Escalation_Process]]
#*# Where security engineering and engineering directors do not sign off or cannot agree on an alternative timeframe, the decision on bug will follow the [[Security/Firefox/Security_Bug_Escalation_Process|Security_Bug_Escalation_Process]]
# After a bug is RESOLVED FIXED it will be assigned to a QE or SoftVision engineer who will attempt to test it in the relevant releases before the bug is VERIFIED FIXED. See the [https://securitywiki.mozilla.org/PostCritSmash Post-CritSmash process document] for current criteria on which bugs we can test.
# After a bug is RESOLVED FIXED it will be assigned to a QE or SoftVision engineer who will attempt to test it in the relevant releases before the bug is VERIFIED FIXED. See the [https://securitywiki.mozilla.org/PostCritSmash Post-CritSmash process document] for current criteria on which bugs we can test.
canmove, Confirmed users
637

edits