Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[META] double check all security releases of D7 and make sure fixes are in Backdrop #180

Closed
12 tasks done
jenlampton opened this issue Feb 7, 2014 · 3 comments
Closed
12 tasks done
Assignees
Milestone

Comments

@jenlampton
Copy link
Member

Since the issues for the security fixes are all private, we may not have caught them in our meta issue of patches that were added to D7 since we forked. This is an issue for double checking that all security fixes to D7 are absolutely positively included in Backdrop 1.0

The process for doing security updates is as follows:

  • Look for the commit that contains only the Drupal release number.
  • Review the diff (or create a patch from it)
  • Apply these same changes to Backdrop.

For reference, here are all D7 releases

@quicksketch
Copy link
Member

It looks like Drupal 7.31 fixed an issue in XML-RPC, but we've removed xmlrpc.php from Backdrop entirely, so that issue does not apply to us. There was also an issue with OpenID, but we've removed that as well. So I've marked the 7.31 task as fixed.

@quicksketch
Copy link
Member

We're (currently) all up-to-date on security releases! Yay!

Let's actually do the "double-checking" part now that all the individual patches are in (or an equivalent).

@quicksketch quicksketch self-assigned this Jan 15, 2015
@quicksketch
Copy link
Member

All of these have now been reviewed a second time to ensure they're all included. We're done here!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants