Security/Archived/Radar

From MozillaWiki
< Security
Revision as of 21:26, 6 January 2012 by Curtisk (talk | contribs)
Jump to navigation Jump to search

Tracking of features / patches needing security review

Bugzilla Sec Queries

  • Sec-Review-Needed
    • Keyword: sec-review-needed
    • whiteboard: (does not contain "[secr:" OR "[rat:"
  • Assigned bugs
    • Keyword: sec-review-needed
    • whiteboard: "[secr:" OR "[rat:"

Review Active

  • Security reviews are on-going
{{#ask: Feature security status::sec-review-activeFeature security health::!Assigned | ?# | ?Feature name# | ?Feature list# | ?Feature version# | ?Feature product manager# | ?Feature lead engineer# | ?Feature security lead# | ?Feature security status# | ?Feature security notes# | ?Modification date# | ?Feature security health# | mainlabel=- | sort=Feature priority,Feature stage | format=template | template=SecurityRadarListTable }}
Feature Feature List Target Rel Prod Mgr Lead Engr Security lead Security status Security notes Last Modified

Review Active & Assigned

{{#ask: Feature security status::sec-review-activeFeature security health::Assigned | ?# | ?Feature name# | ?Feature list# | ?Feature version# | ?Feature product manager# | ?Feature lead engineer# | ?Feature security lead# | ?Feature security status# | ?Feature security notes# | ?Modification date# | ?Feature security health# | mainlabel=- | sort=Feature priority,Feature stage | format=template | template=SecurityRadarListTable }}
Feature Feature List Target Rel Prod Mgr Lead Engr Security lead Security status Security notes Last Modified

Active Bug Reviews

Feature Status Owner Release Tracking
SVG patterns, gradients and filters don't work when SVG is loaded from a data: URL bug 308590 [dveditz]impl rev dholbert r+:bzbarsky sr+:cbiesinger/dholbert FX6
matchMedia support 542058 fuzzer modifications to scan by Jesse David Baron FX6

Review Needed

  • triaged to need review, review unscheduled
{{#ask: Feature security status::sec-review-neededFeature security health::!Assigned | ?# | ?Feature name# | ?Feature list# | ?Feature version# | ?Feature product manager# | ?Feature lead engineer# | ?Feature security lead# | ?Feature security status# | ?Feature security notes# | ?Modification date# | ?Feature security health# | mainlabel=- | sort=Feature version,Feature priority,Feature stage | format=template | template=SecurityRadarListTable }}
Feature Feature List Target Rel Prod Mgr Lead Engr Security lead Security status Security notes Last Modified

Review Needed (Assigned)

  • triaged to need review, assigned to a resource
{{#ask: Feature security status::sec-review-neededFeature security health::Assigned | ?# | ?Feature name# | ?Feature list# | ?Feature version# | ?Feature product manager# | ?Feature lead engineer# | ?Feature security lead# | ?Feature security status# | ?Feature security notes# | ?Modification date# | ?Feature security health# | mainlabel=- | sort=Feature version,Feature priority,Feature stage | format=template | template=SecurityRadarListTable }}
Feature Feature List Target Rel Prod Mgr Lead Engr Security lead Security status Security notes Last Modified

Review Scheduled

  • A review is scheduled
{{#ask: Feature security status::sec-review-sched | ?# | ?Feature name# | ?Feature list# | ?Feature version# | ?Feature product manager# | ?Feature lead engineer# | ?Feature security lead# | ?Feature security status# | ?Feature security notes# | ?Modification date# | ?Feature security health# | mainlabel=- | sort=Feature priority,Feature stage | format=template | template=SecurityRadarListTable }}
Feature Feature List Target Rel Prod Mgr Lead Engr Security lead Security status Security notes Last Modified

Bug reviews Scheduled

Feature Status Owner Release Tracking
Web Apps in Fennec bug 585958 changed to sec-review-needed Fabrice Desre / mfinkle
HTTP Pipelineing bug 264354 changed to sec-review-needed Patrick McManus

Triage Needed

Other Stuff to be Scheduled

Feature Status Owner Release Tracking
libcubeb sound library replacing libsydneyaudio on mozilla-central Unscheduled roc/cpearce/doublec
No more XPConnect between JS and C++ code in DOM workers. Unscheduled
Make all implemented HTML5 inputs accessible. Bonus: implement canvas inner DOM exposure. Unscheduled
Azure: graphics system rewrite Contact email sent jdrew
Accessability Contact initiated dbolter
(e10s) Meetings on going smooney
JetPack Review / meetings ongoing myk/dmason
Sign-in/Sign-out]] Contact initiated thunder(Dan Mills)
OPUS http://tools.ietf.org/html/draft-ietf-codec-opus-05 ETA Need to find owner

Completed Work

Bugzilla

Legend

  Healthy: things are on track
  At Risk: completion of tasks on time is at risk.
  Blocked: security concern is blocking
  Assignd: being worked by someone else.
ETA Estimated date for completion of the current feature task. Overall ETA for the feature is the product release date.

Old Radar Pages

stuff needing reassignment

{{#ask: Feature security status::sec-review-needed [[Feature security notes::~bsterne* ]] | ?# | ?Feature name# | ?Feature list# | ?Feature version# | ?Feature product manager# | ?Feature lead engineer# | ?Feature security lead# | ?Feature security status# | ?Feature security notes# | ?Modification date# | ?Feature security health# | mainlabel=- | format=template | template=SecurityRadarListTable }}
Feature Feature List Target Rel Prod Mgr Lead Engr Security lead Security status Security notes Last Modified