Request to join claim plugin

Previous Topic Next Topic
 
classic Classic list List threaded Threaded
5 messages Options
Reply | Threaded
Open this post in threaded view
|

Request to join claim plugin

Arnaud Tamaillon

Hi,

 

I would like to be approved as a maintainer of the Jenkins claim plugin (https://wiki.jenkins.io/display/JENKINS/Claim+plugin)


Current maintainer, ki82, cc-ed, seems to be inactive for almost one year on github.

I plan to merge a fix to the https://jenkins.io/security/advisory/2017-04-10/ vulnerability as well as at least one other enhancement.

My GitHub id is Greybird.

I am already part of jenkinsci org.

 

Regards,

 

Arnaud

 

--
You received this message because you are subscribed to the Google Groups "Jenkins Developers" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [hidden email].
To view this discussion on the web visit https://groups.google.com/d/msgid/jenkinsci-dev/59e8e449.551d1c0a.c0d74.a7f1%40mx.google.com.
For more options, visit https://groups.google.com/d/optout.
Reply | Threaded
Open this post in threaded view
|

Re: Request to join claim plugin

Daniel Beck

> On 19. Oct 2017, at 19:43, Arnaud <[hidden email]> wrote:
>
> I plan to merge a fix to the https://jenkins.io/security/advisory/2017-04-10/ vulnerability as well as at least one other enhancement.

This is one of the plugins that allow Overall/Administer users to do something that should be limited to Overall/Run Scripts, which is a problem only in very unusual configurations -- so this looks worse than it is. The plugin is still being distributed despite no fix, for that reason.

I told Arnaud that we usually apply a two-week timeout for requests of this sort.

--
You received this message because you are subscribed to the Google Groups "Jenkins Developers" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [hidden email].
To view this discussion on the web visit https://groups.google.com/d/msgid/jenkinsci-dev/E8F960DF-1BFF-4698-B36D-D44FA67D3E03%40beckweb.net.
For more options, visit https://groups.google.com/d/optout.
Reply | Threaded
Open this post in threaded view
|

RE: Request to join claim plugin

Arnaud Tamaillon

Hello Daniel,

 

Thanks.

As the mail used by Christian/ki82 is linked to his previous job, I tried to ping him through LinkedIn so that he has a chance to be actually notified of this thread.

 

Arnaud

 

 

 

De : [hidden email]
Envoyé le :jeudi 19 octobre 2017 23:46
À : [hidden email]
Objet :Re: Request to join claim plugin

 

 

> On 19. Oct 2017, at 19:43, Arnaud <[hidden email]> wrote:

>

> I plan to merge a fix to the https://jenkins.io/security/advisory/2017-04-10/ vulnerability as well as at least one other enhancement.

 

This is one of the plugins that allow Overall/Administer users to do something that should be limited to Overall/Run Scripts, which is a problem only in very unusual configurations -- so this looks worse than it is. The plugin is still being distributed despite no fix, for that reason.

 

I told Arnaud that we usually apply a two-week timeout for requests of this sort.

 

--

You received this message because you are subscribed to the Google Groups "Jenkins Developers" group.

To unsubscribe from this group and stop receiving emails from it, send an email to [hidden email].

To view this discussion on the web visit https://groups.google.com/d/msgid/jenkinsci-dev/E8F960DF-1BFF-4698-B36D-D44FA67D3E03%40beckweb.net.

For more options, visit https://groups.google.com/d/optout.

 

--
You received this message because you are subscribed to the Google Groups "Jenkins Developers" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [hidden email].
To view this discussion on the web visit https://groups.google.com/d/msgid/jenkinsci-dev/59e98c19.1cbf1c0a.64448.63a1%40mx.google.com.
For more options, visit https://groups.google.com/d/optout.
Reply | Threaded
Open this post in threaded view
|

Re: Request to join claim plugin

christian åkerström
Hi,

I would still like to be maintainer of the claim-plugin, but have been very busy during the last months.
If Arnaud want's to share the ownership in the long run I am fine with that.

Christian

On Fri, Oct 20, 2017 at 7:39 AM, Arnaud <[hidden email]> wrote:

Hello Daniel,

 

Thanks.

As the mail used by Christian/ki82 is linked to his previous job, I tried to ping him through LinkedIn so that he has a chance to be actually notified of this thread.

 

Arnaud

 

 

 

De : [hidden email]
Envoyé le :jeudi 19 octobre 2017 23:46
À : [hidden email]
Objet :Re: Request to join claim plugin

 

 

> On 19. Oct 2017, at 19:43, Arnaud <[hidden email]> wrote:

>

> I plan to merge a fix to the https://jenkins.io/security/advisory/2017-04-10/ vulnerability as well as at least one other enhancement.

 

This is one of the plugins that allow Overall/Administer users to do something that should be limited to Overall/Run Scripts, which is a problem only in very unusual configurations -- so this looks worse than it is. The plugin is still being distributed despite no fix, for that reason.

 

I told Arnaud that we usually apply a two-week timeout for requests of this sort.

 

--

You received this message because you are subscribed to the Google Groups "Jenkins Developers" group.

To unsubscribe from this group and stop receiving emails from it, send an email to [hidden email].

To view this discussion on the web visit https://groups.google.com/d/msgid/jenkinsci-dev/E8F960DF-1BFF-4698-B36D-D44FA67D3E03%40beckweb.net.

For more options, visit https://groups.google.com/d/optout.

 

--
You received this message because you are subscribed to the Google Groups "Jenkins Developers" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [hidden email].
To view this discussion on the web visit https://groups.google.com/d/msgid/jenkinsci-dev/59e98c19.1cbf1c0a.64448.63a1%40mx.google.com.

For more options, visit https://groups.google.com/d/optout.

--
You received this message because you are subscribed to the Google Groups "Jenkins Developers" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [hidden email].
To view this discussion on the web visit https://groups.google.com/d/msgid/jenkinsci-dev/CAHcVhVnNV0W8Ogc7XMpqndwPyUBmBpF9OgoCJ8h6pN2_k3M4CA%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.
Reply | Threaded
Open this post in threaded view
|

Re: Request to join claim plugin

Arnaud Tamaillon
Hi Christian,

However, if you feel like you can invest some time to merge PRs and release the plugin in a near future, I'm totally ok to have you stay the sole maintainer.
On the contrary, if you feel like it is a better option to have someone else to manage this, maybe just for some time until you get more on your side, I'm ready to take care.
And of course I have no problem sharing the maintainer role with you (I only asked to be added), as you are far more legitimate than me on the subject.

Feel free to indicate your preference (no offense will be taken :p).

Arnaud

Le lundi 30 octobre 2017 15:35:11 UTC+1, Christian a écrit :
Hi,

I would still like to be maintainer of the claim-plugin, but have been very busy during the last months.
If Arnaud want's to share the ownership in the long run I am fine with that.

Christian

On Fri, Oct 20, 2017 at 7:39 AM, Arnaud <<a href="javascript:" target="_blank" gdf-obfuscated-mailto="c7LwtO3cBQAJ" rel="nofollow" onmousedown="this.href=&#39;javascript:&#39;;return true;" onclick="this.href=&#39;javascript:&#39;;return true;">arnau...@...> wrote:

Hello Daniel,

 

Thanks.

As the mail used by Christian/ki82 is linked to his previous job, I tried to ping him through LinkedIn so that he has a chance to be actually notified of this thread.

 

Arnaud

 

 

 

De : <a href="javascript:" target="_blank" gdf-obfuscated-mailto="c7LwtO3cBQAJ" rel="nofollow" onmousedown="this.href=&#39;javascript:&#39;;return true;" onclick="this.href=&#39;javascript:&#39;;return true;">Daniel Beck
Envoyé le :jeudi 19 octobre 2017 23:46
À : <a href="javascript:" target="_blank" gdf-obfuscated-mailto="c7LwtO3cBQAJ" rel="nofollow" onmousedown="this.href=&#39;javascript:&#39;;return true;" onclick="this.href=&#39;javascript:&#39;;return true;">jenkin...@...
Objet :Re: Request to join claim plugin

 

 

> On 19. Oct 2017, at 19:43, Arnaud <<a href="javascript:" target="_blank" gdf-obfuscated-mailto="c7LwtO3cBQAJ" rel="nofollow" onmousedown="this.href=&#39;javascript:&#39;;return true;" onclick="this.href=&#39;javascript:&#39;;return true;">arnau...@...> wrote:

>

> I plan to merge a fix to the <a href="https://jenkins.io/security/advisory/2017-04-10/" target="_blank" rel="nofollow" onmousedown="this.href=&#39;https://www.google.com/url?q\x3dhttps%3A%2F%2Fjenkins.io%2Fsecurity%2Fadvisory%2F2017-04-10%2F\x26sa\x3dD\x26sntz\x3d1\x26usg\x3dAFQjCNFC_pUW6W2hFGpuW8p9kpJ0n0tD9g&#39;;return true;" onclick="this.href=&#39;https://www.google.com/url?q\x3dhttps%3A%2F%2Fjenkins.io%2Fsecurity%2Fadvisory%2F2017-04-10%2F\x26sa\x3dD\x26sntz\x3d1\x26usg\x3dAFQjCNFC_pUW6W2hFGpuW8p9kpJ0n0tD9g&#39;;return true;">https://jenkins.io/security/advisory/2017-04-10/ vulnerability as well as at least one other enhancement.

 

This is one of the plugins that allow Overall/Administer users to do something that should be limited to Overall/Run Scripts, which is a problem only in very unusual configurations -- so this looks worse than it is. The plugin is still being distributed despite no fix, for that reason.

 

I told Arnaud that we usually apply a two-week timeout for requests of this sort.

 

--

You received this message because you are subscribed to the Google Groups "Jenkins Developers" group.

To unsubscribe from this group and stop receiving emails from it, send an email to <a href="javascript:" target="_blank" gdf-obfuscated-mailto="c7LwtO3cBQAJ" rel="nofollow" onmousedown="this.href=&#39;javascript:&#39;;return true;" onclick="this.href=&#39;javascript:&#39;;return true;">jenkinsci-de...@googlegroups.com.

To view this discussion on the web visit <a href="https://groups.google.com/d/msgid/jenkinsci-dev/E8F960DF-1BFF-4698-B36D-D44FA67D3E03%40beckweb.net" target="_blank" rel="nofollow" onmousedown="this.href=&#39;https://groups.google.com/d/msgid/jenkinsci-dev/E8F960DF-1BFF-4698-B36D-D44FA67D3E03%40beckweb.net&#39;;return true;" onclick="this.href=&#39;https://groups.google.com/d/msgid/jenkinsci-dev/E8F960DF-1BFF-4698-B36D-D44FA67D3E03%40beckweb.net&#39;;return true;">https://groups.google.com/d/msgid/jenkinsci-dev/E8F960DF-1BFF-4698-B36D-D44FA67D3E03%40beckweb.net.

For more options, visit <a href="https://groups.google.com/d/optout" target="_blank" rel="nofollow" onmousedown="this.href=&#39;https://groups.google.com/d/optout&#39;;return true;" onclick="this.href=&#39;https://groups.google.com/d/optout&#39;;return true;">https://groups.google.com/d/optout.

 

--
You received this message because you are subscribed to the Google Groups "Jenkins Developers" group.
To unsubscribe from this group and stop receiving emails from it, send an email to <a href="javascript:" target="_blank" gdf-obfuscated-mailto="c7LwtO3cBQAJ" rel="nofollow" onmousedown="this.href=&#39;javascript:&#39;;return true;" onclick="this.href=&#39;javascript:&#39;;return true;">jenkinsci-de...@googlegroups.com.
To view this discussion on the web visit <a href="https://groups.google.com/d/msgid/jenkinsci-dev/59e98c19.1cbf1c0a.64448.63a1%40mx.google.com?utm_medium=email&amp;utm_source=footer" target="_blank" rel="nofollow" onmousedown="this.href=&#39;https://groups.google.com/d/msgid/jenkinsci-dev/59e98c19.1cbf1c0a.64448.63a1%40mx.google.com?utm_medium\x3demail\x26utm_source\x3dfooter&#39;;return true;" onclick="this.href=&#39;https://groups.google.com/d/msgid/jenkinsci-dev/59e98c19.1cbf1c0a.64448.63a1%40mx.google.com?utm_medium\x3demail\x26utm_source\x3dfooter&#39;;return true;">https://groups.google.com/d/msgid/jenkinsci-dev/59e98c19.1cbf1c0a.64448.63a1%40mx.google.com.

For more options, visit <a href="https://groups.google.com/d/optout" target="_blank" rel="nofollow" onmousedown="this.href=&#39;https://groups.google.com/d/optout&#39;;return true;" onclick="this.href=&#39;https://groups.google.com/d/optout&#39;;return true;">https://groups.google.com/d/optout.

--
You received this message because you are subscribed to the Google Groups "Jenkins Developers" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [hidden email].
To view this discussion on the web visit https://groups.google.com/d/msgid/jenkinsci-dev/8526598e-842b-4ca2-9cc4-26660c264b2d%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.