Code review for security advisory coverage applications

Events happening in the community are now at Drupal community events on www.drupal.org.

This group's purpose is discuss, document, and rally around the code review process for new contributors as well as code reviews for existing modules (outside of the security team), and to help people become (better) code reviewers.

This is not a place to ask someone to review your application.

klausi's picture

Project Applications Virtual Sprint - 16th + 17th August 2013

Start: 
2013-08-16 10:00 - 2013-08-18 10:00 Europe/Vienna
Organizers: 
Event type: 
Sprint

The project application review queue is the place to welcome new Drupal contributors that want to become project maintainers on drupal.org. That queue is always full and we always need help to review projects, so we are planning a joint review sprint to approve users and provide feedback. Code sprints have proven to be an effective tool for productivity on a certain topic, so we want to get together to have some fun and help each other.

The sprint will take place virtually in IRC #drupal-codereview and in Google Hangouts, starting on Friday 16th of August.

Read more
klausi's picture

Help to empower kscheirer

kscheirer has done an amazing job in the project application issue queue by reviewing a lot of projects. Big thanks for that! Now if somebody shows that kind of motivation we should consider that person a candidate for being a git administrator, i.e. someone that is able to approve applicants themselves.

Read more
podarok's picture

Style Manager

Just reviewed a lot of code here
http://drupal.org/node/1995514

Look at video presentation. Impressive work.
Yet one review or possibly just sandbox->project conversion will be apreciated.
The code looks good, all standards and no nitpicks after a few styling commits in sandbox from author.

Thanks for help.

Read more
d34dman's picture

Naming conventions for Entities and how to take take decisions while reviewing Project Applications?

Sorry post got created twice. If somebody could delete thise. Please do.

Link to the other post is below.

http://groups.drupal.org/node/293813

Read more
d34dman's picture

Naming conventions for Entities and how to take take decisions while reviewing Project Applications?

This http://drupal.org/node/1603204 document on drupal.org sounds more like a guideline while developing custom modules for personal use or using the UI to create entities.

When i asked about entity naming convention in #drupal-contribute, xano told me that everything ( entity machine name ) should be prefixed with module name.

While checking a project application, it was found that it used "watchdog" as an entity name. Should it be allowed?

Should

  1. Is it a must that "Machine name of every entity declared by a module should be prefixed with the module name." ? Or,
Read more
jthorson's picture

Unplugging the On-Ramp

TL;DR: A proposal for changes to the scope of the ‘git vetted user’ permission on Drupal.org, and the related project packaging and release capabilities associated with it; changes which would affect not only Drupal’s “new project application” process, but all contrib module authors.

Read more
patrickd's picture

Project Application Sprint @DC Portland

Start: 
2013-05-24 07:00 - 23:00 America/Los_Angeles
Organizers: 
Event type: 
Sprint

To release projects like modules, themes or distributions on drupal.org, contributors have to go through a time consuming process. This process is one of the main on-ramps for new Drupal contributors entering our community ... and we have neglected it for far too long. While we're working on solutions on how to make it easier for people to contribute code - while still assuring a certain level of quality - we must not forget the applicants already in the queue, waiting for their projects to be reviewed.

Read more
jthorson's picture

Project Applications ... remember, this is about the APPLICANTS!

To all reviewers ... I'd like to send everyone a not-so-subtle reminder:

The mission of reviewing Full Project Applications is to ensure that new contributors have a basic understanding of the Drupal community's core values concerning contributing code to Drupal.org, AND to promote lasting, long-term contributing to the project.

Read more
klausi's picture

Automation with Project Applications Scraper and Goutte

The recent little review bonus shitstorm has been a bit of a wakeup call to me. I thought a bit about our goals for the project application process and of course we all know what we want: automation, automation, automation. Last summer I thought that we should postpone that until drupal.org is migrated to Drupal 7 to not waste any time on Drupal 6 coding, but unfortunately the drupal.org upgrade takes longer than expected.

Read more
Quy Ho's picture

Recruit Drupal Technical Architect/Solution Architect/Senior Drupal Developer

Start: 
2013-02-01 (All day) - 2013-05-31 (All day) UTC
Event type: 
User group meeting

We are recruiting "Drupal Technical Architect/Solution Architect/Senior Drupal Developer". Very high salary.

The working location is at e-town, Ho Chi Minh City. However, this position is also open for foreigner candidates or Vietnamese candidates from the North or Central of Vietnam (We offer a relocation allowance up to $5,000).

• At least 6 years of experience in PHP and working at least 2 years in Drupal 7.
• Very strong in Drupal development. Deeply understanding best practices and the Drupal architecture.

Read more
klausi's picture

State of the project application issue queue 2013

Here is a brief status update of what is going on in the project application issue queue lately.

Read more
jnicola's picture

Input validation: Requirement or feature request?

This is a discussion stemming from a module review here:
http://drupal.org/node/1822068

In this situation, the user has submitted a module that works, has been reviewed with no blatant issues found. However, a user can go in to configure the module, and input an incorrect path. This will result in a 404 error.

A_thakur believes that it is a requirement for passing the application process that the path is validated as legitimate.

Read more

Reviews and Mentoring for fr3shw3b

This page serves fr3shw3b's project application reviews and help to project application reviews. This is a part of mentoring to become a code review administrator eventually. add any advice that you may have through comments.

Supersized JQuery Plugin:
http://drupal.org/node/1837780#comment-6776652
http://drupal.org/node/1837780#comment-6897330

Commerce eurobank redirect:
http://drupal.org/node/1850716#comment-6781880
http://drupal.org/node/1850716#comment-6924756

Webform Feedback Module:

Read more
greggles's picture

On motivations of open source contributors

Crossposting to Drupal.org improvements and project application queue as the project application is one of the first experiences that people have with contributing code to Drupal.

I just read and enjoyed this presentation on slideshare: Motivation in FLOSS communities.

Read more
coltrane's picture

Automated static code security analysis with PHP CodeSniffer

I'm working on using PHP Code Sniffer to do automated vulnerability scanning of Drupal code. I've started an issue in the coder module and would love to get some feedback on the approach I'm taking of building an API over phpcs to trace input to output.

http://drupal.org/node/1844870

I hope that this code could make it into Coder module and be used in automated reviews of Drupal projects.

Let me know what you think!

Read more

Mentoring and reviews of user anwar_max

Hi !

This page is used to keep track of anwar_max's reviews and help in the project application queue. We will use this page as reference to his work and to help him become a code review administrator at some point. Please add any advice to you might have in the comments.

Manual reviews

tablebooker:
http://drupal.org/node/1854328#comment-6799656
http://drupal.org/node/1854328#comment-6814106
http://drupal.org/node/1854328#comment-6814260

Vocabulary image:
http://drupal.org/node/1637566#comment-6799778
http://drupal.org/node/1637566#comment-6814196

Read more
arun ak's picture

Drupal 7 is faster than Drupal 6.

Yes
22% (2 votes)
No
78% (7 votes)
Total votes: 9

Reviews and mentoring of user gisle

This wiki page is created to keep track of gisle's manual reviews of projects in the project application queue. As a rookie reviewer I hope to get some advice from more experienced reviewers. Please use the comment field to add your advice, corrections, and observations.

Partcipation in Project Applications project.

Reviews

Read more
cubeinspire's picture

Enabling the overlay module for anonymous: Security risks

Hi,

I'm reviewing a sandbox project for Drupal7 called Overlay Links that encourage to enable the overlay module for anonymous users.
review comment: http://drupal.org/node/1811482#comment-6609236

I've read on some blog that doing this have security concerns, but there was no more details about that.
blog link: http://www.drupalgardens.com/documentation/site-management/admin-theme

Do you have any details about the security implications of enabling the permission Access the administrative overlay to anonymous users ?

Read more
Subscribe with RSS Syndicate content

Code review for security advisory coverage applications

Group organizers

Group notifications

This group offers an RSS feed. Or subscribe to these personalized, sitewide feeds: