-
Notifications
You must be signed in to change notification settings - Fork 1.9k
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Merge branch 'jetty-12.0.x' into error-page-buff-size
- Loading branch information
Showing
1,650 changed files
with
22,786 additions
and
50,964 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,5 +1,5 @@ | ||
blank_issues_enabled: true | ||
contact_links: | ||
- name: Jetty Security Reports | ||
url: https://eclipse.dev/jetty/security_reports.php | ||
url: https://jetty.org/security.html | ||
about: Please raise security issues here. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -52,3 +52,5 @@ bin/ | |
|
||
# reports | ||
reports/ | ||
|
||
.launchable |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,15 +1,15 @@ | ||
# Contributing to Jetty | ||
|
||
Contributions are always welcome! | ||
Please see our [Contribution Guide](https://eclipse.dev/jetty/documentation/contribution-guide/index.html) for instructions on how to set up your development environment, as well as information on our processes and coding standards. | ||
Please see our [Contribution Guide](https://jetty.org/docs/contribution-guide/index.html) for instructions on how to set up your development environment, as well as information on our processes and coding standards. | ||
|
||
Here are some quick links to other useful resources: | ||
|
||
* [**Source code.**](https://github.com/jetty/jetty.project) Jetty's canonical git repository is located on GitHub at https://github.com/jetty/jetty.project. | ||
|
||
* [**Mailing list.**](https://accounts.eclipse.org/mailing-list/jetty-users) The [`[email protected]`](mailto:[email protected]) mailing list is a forum for technical discussion. | ||
|
||
* [**Issue tracking.**](https://github.com/jetty/jetty.project/issues) We use [GitHub Issues](https://github.com/eclipse/jetty.project/issues) to track ongoing development and issues. | ||
* [**Issue tracking.**](https://github.com/jetty/jetty.project/issues) We use [GitHub Issues](https://github.com/jetty/jetty.project/issues) to track ongoing development and issues. | ||
|
||
|
||
## Eclipse Contributor Agreement | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,9 +1,10 @@ | ||
# GPG Release Key Fingerprints | ||
Jan Bartel <[email protected]> AED5 EE6C 45D0 FE8D 5D1B 164F 27DE D4BF 6216 DB8F | ||
Jesse McConnell <[email protected]> 2A68 4B57 436A 81FA 8706 B53C 61C3 351A 438A 3B7D | ||
Joakim Erdfelt <[email protected]> 5989 BAF7 6217 B843 D66B E55B 2D0E 1FB8 FE4B 68B4 | ||
Joakim Erdfelt <[email protected]> B59B 67FD 7904 9843 67F9 3180 0818 D9D6 8FB6 7BAC | ||
Joakim Erdfelt <[email protected]> BFBB 21C2 46D7 7768 3628 7A48 A04E 0C74 ABB3 5FEA | ||
Simone Bordet <[email protected]> 8B09 6546 B1A8 F026 56B1 5D3B 1677 D141 BCF3 584D | ||
Olivier Lamy <[email protected]> F254 B356 17DC 255D 9344 BCFA 873A 8E86 B437 2146 | ||
Ludovic Orban <[email protected]> CD38 A1DA DA34 13BE 96DF 547F 3D14 6A4A 1C58 367E | ||
Jan Bartel <[email protected]> AED5 EE6C 45D0 FE8D 5D1B 164F 27DE D4BF 6216 DB8F | ||
Jesse McConnell <[email protected]> 2A68 4B57 436A 81FA 8706 B53C 61C3 351A 438A 3B7D | ||
Joakim Erdfelt <[email protected]> 5989 BAF7 6217 B843 D66B E55B 2D0E 1FB8 FE4B 68B4 | ||
Joakim Erdfelt <[email protected]> B59B 67FD 7904 9843 67F9 3180 0818 D9D6 8FB6 7BAC | ||
Joakim Erdfelt <[email protected]> BFBB 21C2 46D7 7768 3628 7A48 A04E 0C74 ABB3 5FEA | ||
Simone Bordet <[email protected]> 8B09 6546 B1A8 F026 56B1 5D3B 1677 D141 BCF3 584D | ||
Olivier Lamy <[email protected]> F254 B356 17DC 255D 9344 BCFA 873A 8E86 B437 2146 | ||
Ludovic Orban <[email protected]> CD38 A1DA DA34 13BE 96DF 547F 3D14 6A4A 1C58 367E | ||
Lachlan Roberts <[email protected]> 75DE 085F 73C1 2232 6066 3C24 5663 FB7A 8FF7 E348 |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -2,15 +2,15 @@ | |
|
||
## Supported Versions | ||
|
||
All [stable versions](https://eclipse.dev/jetty/download.php) of jetty are actively supported for security issues. [Deprecated versions](https://eclipse.dev/jetty/download.php) may be supported for serious security issues or on a commercial support basis. | ||
All [stable versions](https://jetty.org/download.html) of jetty are actively supported for security issues. [Deprecated versions](https://jetty.org/download.html) may be supported for serious security issues or on a commercial support basis. | ||
|
||
## Reporting a Vulnerability | ||
|
||
Do not open a public issue to report a security vulnerability. Please send a message to [email protected] and we will create a private issue in which the issue can be triaged and handled. | ||
|
||
## Handling a Vulnerability | ||
|
||
The [following checklist](https://eclipse.dev/jetty/security_processes.php) is used to handle security issues: | ||
The following checklist is used to handle security issues: | ||
|
||
- [ ] On receipt of a security report via [email protected] or other channels, if it cannot be trivially dismissed (already fixed, known not a problem, etc.), then a Github security advisory is created by project leadership. | ||
- [ ] Copy this list as a markdown in the security advisory for tracking the completion of various tasks. | ||
|
@@ -20,9 +20,9 @@ The [following checklist](https://eclipse.dev/jetty/security_processes.php) is u | |
- [ ] If the vulnerability cannot be confirmed then close the security advisory, else continue. | ||
- [ ] Generate a CVE score and add it to the advisory description. | ||
- [ ] Identify a CWE Definition and add it to the advisory description. | ||
- [ ] Identify vulnerable version(s), including current and past versions that are affected (e.g. 9.4.0 through 9.4.35, and 10.0.0.alpha1 through 10.0.0.beta3…etc.) | ||
- [ ] Identify vulnerable version(s), including current and past versions that are affected (e.g. 9.4.0 through 9.4.35, and 10.0.0.alpha1 through 10.0.0.beta3 etc.) | ||
- [ ] Identify and document workaround(s), if applicable, in the comments of the security advisory. | ||
- [ ] Open an [Gitlab@Eclipse EMO CVE issue](https://gitlab.eclipse.org/eclipsefdn/emo-team/emo/-/issues/new?issuable_template=cve) to have a CVE allocated. | ||
- [ ] Open an [Gitlab@Eclipse CVE Assignment](https://gitlab.eclipse.org/security/cve-assignement/-/issues/new) to have a CVE allocated. | ||
The issue should be opened under the "Eclipse Foundation" > "EMO Team" > "EMO" section as a "cve" description, with the "This issue is confidential" checkbox checked. | ||
Follow the template for what details are necessary to file for a CVE. | ||
- [ ] Once the CVE is allocated update the Security Advisory with the number | ||
|
Oops, something went wrong.