Blog

New symfony security policy

Jobeet, learn symfony step by step, 24 days, 1 hour a day

« Back to the Blog

Categories

Feeds

feed Posts feed

comments feed Comments feed

Be trained by symfony experts
Jan 21: Paris (1.2 - Francais)
Feb 04: Montpellier (1.2 - Français)
Feb 18: Paris (1.2 - Francais)
Mar 11: Nantes (1.2 - Français)
Mar 18: Paris (1.2 - Français)
and more...

Archives

Creative Commons License This work is licensed under a Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 Unported License.

Last week we've fixed a security bug allowing XSS attacks in certain circumstances. The related ticket was opened more than a year ago.

You may be wondering why it has been taking us such a long time to react. Here's the main reason: we had not a very strong security alert reporting and qualifying process. This has been fixed recently.

So as of now, if you find a security bug in symfony, please send an email to security at symfony-project.com, with as much details as you can and ideally a patch if you can provide one. Your message will be forwarded to the core team internal mailing-list, qualified and addressed as quickly as possible. The whole procedure is detailed in a dedicated section of the brand new how to contribute page in the symfony wiki.

By the way don't hesitate to read the whole how to contribute page on the wiki, as there's plenty of information on how you can help the symfony project.

Comments comments feed

gravatar
#1 Eric Bartels said about 3 hours later

I'm glad to see that security is taken seriously!

Thanks for that. Keep on your good work :)

gravatar
#2 Joshua May said about 4 hours later

pookey will be happy!

But really, this is a good thing. Another reason symfony is #1, really.

gravatar
#3 hadrien said about 6 hours later

i think it's good you take care about security, but i wonder how you review tickets and affect priority to them...

gravatar
#4 Ian P. Christian said about 7 hours later

@notjosh - indeed - I am happy :)

I was deliberately playing Devil's Advocate on my blog post related to this, in an effort to get things moving. I'm please we as a community have managed to get this ball rolling in the right direction.

gravatar
#5 Hugo said about 10 hours later

Great idea :D