Skip to content

Commit 7242478

Browse files
committed
doc: add request to hold off publicising sec releases
- We've often seen tweets go out early before announcement and other parts of the security release complete - Make an explicit ask that collaborators avoid doing this by gating on the tweet from the Node.js account - Releasers would still be free to tweet earlier as they know when the process is complete. Signed-off-by: Michael Dawson <mdawson@devrus.com>
1 parent 7796692 commit 7242478

File tree

1 file changed

+8
-0
lines changed

1 file changed

+8
-0
lines changed

doc/contributing/security-release-process.md

+8
Original file line numberDiff line numberDiff line change
@@ -111,6 +111,7 @@ out a better way, forward the email you receive to
111111
`oss-security@lists.openwall.com` as a CC.
112112

113113
* [ ] Create a new issue in [nodejs/tweet][]
114+
114115
```text
115116
Security release pre-alert:
116117
@@ -123,6 +124,13 @@ out a better way, forward the email you receive to
123124
https://nodejs.org/en/blog/vulnerability/month-year-security-releases/
124125
```
125126

127+
We specifically ask that collaborators other than the releasers and security
128+
steward working on the security release do not tweet or publicise the release
129+
until the tweet from the Node.js twitter handle goes out. We have often
130+
seen tweets sent out before the release and associated announcements are
131+
complete which may confuse those waiting for the release and also takes
132+
away from the work the releasers have put into shipping the releases.
133+
126134
* [ ] Request releaser(s) to start integrating the PRs to be released.
127135

128136
* [ ] Notify [docker-node][] of upcoming security release date: _**LINK**_

0 commit comments

Comments
 (0)