Mailinglist Archive: opensuse-buildservice (158 mails)

< Previous Next >
[opensuse-buildservice] OBS 2.2 Beta 1
  • From: Adrian Schröter <adrian@xxxxxxx>
  • Date: Thu, 09 Dec 2010 14:48:28 +0100
  • Message-id: <20101209164818.0A6F43C539A9@xxxxxxxxxxxx>

OBS 2.2 Beta 1 is released
==========================

We release the first version of OBS 2.2, this release provides in first
place the project read access feature. This feature got implemented by the
LinuxFoundation.

Also LDAP group support has been added as major feature provided by Intel.

Another heavy change is the usage of XSS protection libraries. This has been
implemented in the webui.

Please read the README.UPDATERS file when doing the update.

It got released to the ususal places, tagged as version 2.1.69:

Appliance: http://en.opensuse.org/openSUSE:Build_Service_Appliance
Packages: http://download.opensuse.org/repositories/openSUSE:/Tools:/Unstable/
Git: http://www.gitorious.org/opensuse/build-service/commits/2.2


Areas which should be tested esp:
=================================
* The XSS protection libraries may break some web interface.
* The "project" read access protection may still get be tricked some how.
It has been reworked heavily to achieve the best possible protection,
but a heavy review is still very desirable.

=> do not protect live critical secrets with it yet :)


Existing problems which need to be fixed before 2.2 final release
=================================================================

* webui is generating corrupt project meta data -> add repo is failing
* webui is caching also secret data, exposing hidden projects.



--
Adrian Schroeter
SUSE Linux Products GmbH
email: adrian@xxxxxxx

--
To unsubscribe, e-mail: opensuse-buildservice+unsubscribe@xxxxxxxxxxxx
For additional commands, e-mail: opensuse-buildservice+help@xxxxxxxxxxxx

< Previous Next >
This Thread
  • No further messages