You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to OpenRefine Development
Good Morning! I initially posted in the OpenRefine group and was directed to the dev group.
I am performing a risk assessment for the use of this product on behalf of my organization. I've reviewed documentation relating to CI/CD testing with Cyprus.io and the Security tab on GitHub.
-In addition to these measures are there any security validation checks or code review for vulnerabilities that takes place internal to the development process?
-Would you consider including a hash with product downloads on openregine.org?
Thank you for you time.
Antonin Delpeuch (lists)
unread,
Nov 25, 2022, 4:21:32 AM11/25/22
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to openref...@googlegroups.com
Hi Daniel,
Sorry for the delay in replying to this.
- pull requests are reviewed with security in mind, as a part of the
normal development process
- hashes have been published for some releases in the past but this has
not been systematically done because of the overhead it incurs on the
release process. But I am hoping to be able to automatize that and
publish such hashes on our website. I have opened a ticket about this:
https://github.com/OpenRefine/openrefine.org/issues/158
Note that this mailing list is closing soon but feel free to reach out
on the forum for follow-up discussion:
https://forum.openrefine.org/