Code review for security advisory coverage applications

Events happening in the community are now at Drupal community events on www.drupal.org.

This group's purpose is discuss, document, and rally around the code review process for new contributors as well as code reviews for existing modules (outside of the security team), and to help people become (better) code reviewers.

This is not a place to ask someone to review your application.

klausi's picture

Review Bonus: The Force awakens

Dear fellow Jedis and Padawans,

we live in dark times. The Review Bonus queue is currently peaking at 37 issues and many new contributors are suffering. The ever expanding empire is luring them to the dark side where there is chaos, anarchy and security vulnerabilities in unreviewed code. The Jedi council is weakened, we are caught in politics such as client projects.

Read more

Reviewing and Mentoring for Arpit Jalan

I would like to thank all the mentors and reviewers to help me take a deeper look to Drupal. It has clean, secure and fast code compared to other projects be it Core or contrib. I realized project applications play a major role in vetting and reviewing new projects, so I wanted to do what I can.

Here are the lists of work which I have contributed in reviewing the projects:

  1. oFeatures Customer Service

  2. Multimedia Block

Read more

Reviews and Mentoring for Prashant.c

This page serves Prashant.c's project application reviews and help to project application reviews.
https://www.drupal.org/project/issues/search/projectapplications?project...

This is a part of mentoring to become a code review administrator eventually.

I would keep on adding projects reviews in wiki page.

Below are the project applications I reviewed/following:

[D7] User activity log

Read more
manjit.singh's picture

Suggestions/Query related to our review process

Some steps of current review process:

  1. Users are creating sandbox for their new projects and get reviews from other community members.
  2. Other reviewers give him instructions and some guidelines related to code/Security etc.
  3. After too many reviews and changes in his code, Project finally gets approved, which upgrades his permission to create a full project.
  4. So my question here is

    Why we are giving access to users to create full project without any code review?

Read more

Reviews and Mentoring for ruslan_03492

This wiki page is created to keep track of ruslan_03492 manual reviews of projects in the project application queue. As a reviewer I hope to get some advice from more experienced reviewers. Please use the comment field to add your advice, corrections, and observations.

Reviews List:

Full Project Promote Issues:

Read more

Reviews and mentoring for maen

This page serves maen's project application reviews and help to project application reviews. This is a part of mentoring to become a code review administrator eventually. Add any advice that you may have through comments.

My reviews

<

ul>

  • Simple adsense
  • Search Replace Blocks...
  • Xing Connect
  • Read more

    [D7] Security review check list?

    First of all, I would like to thank every one of you for the welcome and support for me to become a git admin.

    While there is a neat documentation for the review process itself, I think it would be easier if we have a check list of security reviews. Automated tests can detect printing $_GET vars, etc, but there is a pattern of security issues in many applications.

    I'm collecting points to write a wiki page. So far, I have written down these. If you have any suggestions of a repeated security issue pattern, please share!

    Read more

    Reviews and Mentoring for Pravin Ajaaz

    This wiki page is created to keep track of my project application reviews to get advice and mentored by Git administrators and anyone else who might have suggestions, advices, etc.

    I always loved to contribute back. Now I decided to start it but it's hard for me to properly review other's code. I hope I will improve eventually and be a good part of the community.

    Read more
    darol100's picture

    Single Project Promotion Documentation

    Problem/Motivation

    At the moment we do not have any information that talks about Single Project Promotion. We are asking users if they want to have a single project promotion but if you are a new user this can be confusing as to what exactly are the differences between single project promotion and full promotion.

    Solution

    Created text that talks about single project promotion and provide a URL to new user to have a better understanding.

    Read more

    Reviews and Mentoring for Ayesh

    This wiki page is created to keep track of Ayesh's Project application reviews for him to get advice and mentored by Git administrators and anyone else who might have suggestions, advices, etc.

    Read more

    Reviews and Mentoring for darol100

    I have been reviewing projects since last year. I would like to become a code review administrator.

    I would keep on adding projects reviews in wiki page.

    https://www.drupal.org/project/issues/search/projectapplications?project...

    Read more

    Reviews and Mentoring for RavindraSingh

    RavindraSingh reviews for various new project applications. Having hands on experience in reviewing/auditing contributed modules also. This is a part of mentoring to become a code review administrator eventually.

    My main focus area is to check security issues/thridparty dependency in application. I take help from http://pareview.sh/ and some contrib modules like:
    https://www.drupal.org/project/xhprof
    https://www.drupal.org/project/coder
    https://www.drupal.org/project/security_check
    https://www.drupal.org/project/security_review
    https://www.drupal.org/project/dcq

    I represented all these things to Drupalers in a presentation (http://www.slideshare.net/ravindrasingh251/checklist-for-drupal-site-dev...)
    AND after all these thing I do manual test.

    Read more

    Reviews and Mentoring for deepakaryan1988

    This page serves deepakaryan1988's project application reviews and help to project application reviews. This is a part of mentoring to become a code review administrator eventually.

    I have been reviewing projects from last year. I would like to actively review more projects from now on and become a code review administrator eventually.

    https://www.drupal.org/project/issues/search/projectapplications?project...

    Read more
    davidhernandez's picture

    Changes to the project application review process

    The proposed changes to the review process and policies has been posted for public review. You can find it here - https://www.drupal.org/node/2453587

    If you have any comments, please add them on that issue.

    Read more

    Reviews and Mentoring for Manjit.Singh

    This page serves project reviews of Manjit.Singh.

    https://www.drupal.org/project/issues/search/projectapplications?project...

    I have been reviewing projects from past two years, and also submitting some patches in Drupal8.

    I would keep on adding projects reviews in wiki page.

    Security issues:

    [D7] Global Regex : https://www.drupal.org/node/2674524#comment-10897518

    Read more

    Reviews Full Project Promote Issue by Rahul Seth

    This wiki page is created to keep track of Rahul Seth's reviews of projects in the project application queue. For experienced reviewers, please use the comment field to add your advice, corrections, and observations. I'll appreciate your efforts.

    Reviews List:

    Full Project Promote Issues:

    1. [D7] Select registration roles
    Read more
    kscheirer's picture

    "git vetted user" for a Feature module

    I'm inclined to say we cannot grant "git vetted user" status based on a features export, since there is no original code. These modules should be eligible for a single project promotion though. I couldn't find that documented anywhere though, to make it official.

    Read more

    Reviews and mentoring for Swarnendu-Dutta

    This wiki page is created to keep track of Swarnendu-Dutta's manual reviews of projects in the project application queue. As a reviewer I hope to get more advice from more experienced reviewers. Please use the comment field to add your advice, corrections and observations.

    Read more

    Reviews and Mentoring for Sagar Ramgade

    This wiki page is created to keep track of Sagar Ramgade's manual reviews of projects in the project application queue. As a reviewer I hope to get some advice from more experienced reviewers. Please use the comment field to add your advice, corrections, and observations.

    Reviews List:

    Full Project Promote Issues:

    <

    ol>

    Read more
    naveenvalecha's picture

    code review sprint, Feburary 8, during Drupal Camp Mumbai

    Start: 
    2015-02-08 (All day) Asia/Kolkata
    Organizers: 
    Event type: 
    Sprint

    The goal of this sprint is to work on project application reviews, particularly helping the Git admins reduce the current needs review backlog.

    Please signup if you are interested in participating. Collaboration for the sprint will happen in the #drupal-codereview IRC channel.

    Applications that needs Review :
    https://www.drupal.org/project/issues/projectapplications?text=&status=8...

    Helping links :

    Read more
    Subscribe with RSS Syndicate content

    Code review for security advisory coverage applications

    Group organizers

    Group notifications

    This group offers an RSS feed. Or subscribe to these personalized, sitewide feeds: