Skip to content
This repository has been archived by the owner on Nov 16, 2022. It is now read-only.

Keep up with radar and queue changes #924

Closed
wants to merge 8 commits into from
Closed

Conversation

chadwhitacre
Copy link
Contributor

@chadwhitacre chadwhitacre commented Nov 28, 2016

Now that we have chat again (#913), we should retire the radar tickets here in GitHub, since those were invented to do the thing that chat is for. While we're at it we should clean up our queue docs since those are also now out of date and closely related to the radar.

@chadwhitacre
Copy link
Contributor Author

HackerOne has severity ratings now, so we can set those there. Can we also add counts to http://inside.gratipay.com/appendices/disclosures?

@chadwhitacre
Copy link
Contributor Author

The use:

none, low, medium, high, critical

Which maps easily to our risk ratings:

none, theoretical, mild, moderate, severe

@chadwhitacre
Copy link
Contributor Author

@dmk246 I have a project for you! :-) Would you be willing to go through our lists of closed and still-open H1 tickets, and set a severity rating for each one? The field is on the upper right when you bring up a ticket, and it looks like this:

screen shot 2016-11-29 at 10 59 01 am

We just need to click "Add" and select a rating for each one of our tickets. Here's how our labels
(which are defined in our program) map to theirs:

Ours ("risk") Theirs ("severity")
n/a No Rating
none None
theoretical Low
mild Medium
moderate High
severe Critical

In the future, every new ticket should get a rating (we'll work on that later :). The task right now is to backfill that field for all previous tickets—we've already categorized them ourselves, we just to record the info in HackerOne. Here are the lists of tickets with our categorizations:

Make sense? Up for it? :-)

@chadwhitacre chadwhitacre mentioned this pull request Nov 29, 2016
@chadwhitacre chadwhitacre changed the title Rewriting radar and queue docs Remove radar and queue docs Nov 29, 2016
@chadwhitacre chadwhitacre changed the title Remove radar and queue docs Keep up with radar and queue changes Nov 29, 2016
@chadwhitacre
Copy link
Contributor Author

chadwhitacre commented Nov 29, 2016

@dmk246 Note that we don't need to do the CVSS calculator right now, just the simple five-point scale. It does say "or". ;-)


screen shot 2016-11-29 at 11 21 26 am

@chadwhitacre
Copy link
Contributor Author

chadwhitacre commented Nov 29, 2016

I've emailed H1 about getting an API key so we can update the disclosures page to use the new severity ratings. Those are only available in the API proper. Turns out we've been using a public API so far.

@dmk246
Copy link

dmk246 commented Nov 30, 2016

@whit537 sorry for the delay been working on a few things. I am up for it ....let me review your comments....(note I may have questions) ... thanks!

@chadwhitacre
Copy link
Contributor Author

What delay? :)

@chadwhitacre
Copy link
Contributor Author

Ftr @dmk246 and I were able to talk through this in person. 👍

@dmk246
Copy link

dmk246 commented Dec 1, 2016

@whit537 where was the link to the tickets that need altered that we looked at yesterday ? I have looked everywhere that I can think .. but obviously I haven't seemed to find it... Sorry and Thanks

@chadwhitacre
Copy link
Contributor Author

@dmk246 Here you go! Are these the right ones? :-)

@dmk246
Copy link

dmk246 commented Dec 1, 2016

Thanks @whit537 Exactly!!

@dmk246
Copy link

dmk246 commented Dec 4, 2016

These are done! Note, under open tickets, https://hackerone.com/reports/143139 was listed as a theoretical risk, aka low risk, but @whit537 had set it to high risk on Nov. 29th ... just wanted to make you aware of this, so in case you needed to change it in other locations. :)

@chadwhitacre
Copy link
Contributor Author

Awesome, thanks @dmk246! I'll proceed with the updates to the disclosures page now that we have all the tickets categorized ... and I'll take a look at that high/moderate one!

@chadwhitacre
Copy link
Contributor Author

Okay, I made some progress on this. Hopefully I can make a commit soon!

@chadwhitacre
Copy link
Contributor Author

I turned off the radar rotation in @gratipay-bot in gratipay/bot@0002837 and gratipay/bot@c4cba99.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants