Request to join claim plugin

34 views
Skip to first unread message

Arnaud

unread,
Oct 19, 2017, 1:43:47 PM10/19/17
to Jenkins Developers, christia...@autoliv.com

Hi,

 

I would like to be approved as a maintainer of the Jenkins claim plugin (https://wiki.jenkins.io/display/JENKINS/Claim+plugin)


Current maintainer, ki82, cc-ed, seems to be inactive for almost one year on github.

I plan to merge a fix to the https://jenkins.io/security/advisory/2017-04-10/ vulnerability as well as at least one other enhancement.

My GitHub id is Greybird.

I am already part of jenkinsci org.

 

Regards,

 

Arnaud

 

Daniel Beck

unread,
Oct 19, 2017, 5:46:43 PM10/19/17
to jenkin...@googlegroups.com

> On 19. Oct 2017, at 19:43, Arnaud <arnau...@gmail.com> wrote:
>
> I plan to merge a fix to the https://jenkins.io/security/advisory/2017-04-10/ vulnerability as well as at least one other enhancement.

This is one of the plugins that allow Overall/Administer users to do something that should be limited to Overall/Run Scripts, which is a problem only in very unusual configurations -- so this looks worse than it is. The plugin is still being distributed despite no fix, for that reason.

I told Arnaud that we usually apply a two-week timeout for requests of this sort.

Arnaud

unread,
Oct 20, 2017, 1:39:45 AM10/20/17
to jenkin...@googlegroups.com

Hello Daniel,

 

Thanks.

As the mail used by Christian/ki82 is linked to his previous job, I tried to ping him through LinkedIn so that he has a chance to be actually notified of this thread.

 

Arnaud

 

 

 

De : Daniel Beck
Envoyé le :jeudi 19 octobre 2017 23:46
À : jenkin...@googlegroups.com
Objet :Re: Request to join claim plugin

--

You received this message because you are subscribed to the Google Groups "Jenkins Developers" group.

To unsubscribe from this group and stop receiving emails from it, send an email to jenkinsci-de...@googlegroups.com.

To view this discussion on the web visit https://groups.google.com/d/msgid/jenkinsci-dev/E8F960DF-1BFF-4698-B36D-D44FA67D3E03%40beckweb.net.

For more options, visit https://groups.google.com/d/optout.

 

Christian

unread,
Oct 30, 2017, 10:35:11 AM10/30/17
to jenkin...@googlegroups.com
Hi,

I would still like to be maintainer of the claim-plugin, but have been very busy during the last months.
If Arnaud want's to share the ownership in the long run I am fine with that.

Christian

On Fri, Oct 20, 2017 at 7:39 AM, Arnaud <arnau...@gmail.com> wrote:

Hello Daniel,

 

Thanks.

As the mail used by Christian/ki82 is linked to his previous job, I tried to ping him through LinkedIn so that he has a chance to be actually notified of this thread.

 

Arnaud

 

 

 

De : Daniel Beck
Envoyé le :jeudi 19 octobre 2017 23:46
À : jenkin...@googlegroups.com
Objet :Re: Request to join claim plugin

 

 

> On 19. Oct 2017, at 19:43, Arnaud <arnau...@gmail.com> wrote:

>

> I plan to merge a fix to the https://jenkins.io/security/advisory/2017-04-10/ vulnerability as well as at least one other enhancement.

 

This is one of the plugins that allow Overall/Administer users to do something that should be limited to Overall/Run Scripts, which is a problem only in very unusual configurations -- so this looks worse than it is. The plugin is still being distributed despite no fix, for that reason.

 

I told Arnaud that we usually apply a two-week timeout for requests of this sort.

 

--

You received this message because you are subscribed to the Google Groups "Jenkins Developers" group.

To unsubscribe from this group and stop receiving emails from it, send an email to jenkinsci-dev+unsubscribe@googlegroups.com.

--
You received this message because you are subscribed to the Google Groups "Jenkins Developers" group.
To unsubscribe from this group and stop receiving emails from it, send an email to jenkinsci-dev+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/jenkinsci-dev/59e98c19.1cbf1c0a.64448.63a1%40mx.google.com.

Arnaud Tamaillon

unread,
Oct 30, 2017, 4:09:35 PM10/30/17
to Jenkins Developers
Hi Christian,

However, if you feel like you can invest some time to merge PRs and release the plugin in a near future, I'm totally ok to have you stay the sole maintainer.
On the contrary, if you feel like it is a better option to have someone else to manage this, maybe just for some time until you get more on your side, I'm ready to take care.
And of course I have no problem sharing the maintainer role with you (I only asked to be added), as you are far more legitimate than me on the subject.

Feel free to indicate your preference (no offense will be taken :p).

Arnaud


Le lundi 30 octobre 2017 15:35:11 UTC+1, Christian a écrit :
Hi,

I would still like to be maintainer of the claim-plugin, but have been very busy during the last months.
If Arnaud want's to share the ownership in the long run I am fine with that.

Christian
On Fri, Oct 20, 2017 at 7:39 AM, Arnaud <arnau...@gmail.com> wrote:

Hello Daniel,

 

Thanks.

As the mail used by Christian/ki82 is linked to his previous job, I tried to ping him through LinkedIn so that he has a chance to be actually notified of this thread.

 

Arnaud

 

 

 

De : Daniel Beck
Envoyé le :jeudi 19 octobre 2017 23:46
À : jenkin...@googlegroups.com
Objet :Re: Request to join claim plugin

 

 

> On 19. Oct 2017, at 19:43, Arnaud <arnau...@gmail.com> wrote:

>

> I plan to merge a fix to the https://jenkins.io/security/advisory/2017-04-10/ vulnerability as well as at least one other enhancement.

 

This is one of the plugins that allow Overall/Administer users to do something that should be limited to Overall/Run Scripts, which is a problem only in very unusual configurations -- so this looks worse than it is. The plugin is still being distributed despite no fix, for that reason.

 

I told Arnaud that we usually apply a two-week timeout for requests of this sort.

 

--

You received this message because you are subscribed to the Google Groups "Jenkins Developers" group.

To unsubscribe from this group and stop receiving emails from it, send an email to jenkinsci-de...@googlegroups.com.

--
You received this message because you are subscribed to the Google Groups "Jenkins Developers" group.
To unsubscribe from this group and stop receiving emails from it, send an email to jenkinsci-de...@googlegroups.com.
Reply all
Reply to author
Forward
0 new messages