Branch: refs/heads/master Home: https://github.com/xwiki/xwiki-dev-llm Commit: 02ed9d4f11fa5923322991c2759890a7995e8385 https://github.com/xwiki/xwiki-dev-llm/commit/02ed9d4f11fa5923322991c2759890... Author: Michael Hamann <[email protected]> Date: 2026-09-28 (Mon, 28 Sep 2026) Changed paths: M xwiki/okf/processes/security-policy.md M xwiki/skills/xwiki-security-advisory/SKILL.md Log Message: ----------- [Misc] Follow GitHub's version range best practices and leave the PoC out of security advisories * xwiki-security-advisory: one band per fix with the band's own upper bound as the only patched version, following GitHub's best practices (GHSA-wcg9-pgqv-xm5v as model); past repository advisories' open-ended ranges were rewritten by GitHub's curators and are no example * xwiki-security-advisory: verify the first affected release against the code history (backports, dependencies of the attack), keep JIRA's Affects/Fix Version/s in sync (or tell the user what to set) and optionally link the issues that introduced the vulnerable code; JIRA version names use the Maven syntax * xwiki-security-advisory: check the module history (renames, splits) and modules repackaging the vulnerable one * xwiki-security-advisory, security-policy.md: no PoC in advisories, a change from past practice proposed on the forum Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]> Commit: bb51ff9e83a88bc5d8bdabe7453ba73ea9ae9c3f https://github.com/xwiki/xwiki-dev-llm/commit/bb51ff9e83a88bc5d8bdabe7453ba7... Author: Michael Hamann <[email protected]> Date: 2026-09-28 (Mon, 28 Sep 2026) Changed paths: M xwiki/skills/xwiki-security-advisory/SKILL.md Log Message: ----------- [Misc] Document the credit types and the Security team collaborator of security advisories * xwiki-security-advisory: finder vs. reporter credit types, following GitHub's definitions * xwiki-security-advisory: create the advisory with a JSON payload, then add the `security` team through an update, as the create request rejects collaborating_teams Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]> Commit: b32a03f88eb4463e2ec18b4e315e6c3cfa1a7e6d https://github.com/xwiki/xwiki-dev-llm/commit/b32a03f88eb4463e2ec18b4e315e6c... Author: Michael Hamann <[email protected]> Date: 2026-09-30 (Wed, 30 Sep 2026) Changed paths: M xwiki/skills/xwiki-security-advisory/SKILL.md Log Message: ----------- [Misc] Use the same Security team slug for xwiki-contrib security advisories * xwiki-security-advisory: the Security team's slug is `security` in both the xwiki and xwiki-contrib organizations, so there is no need to look it up Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]> Commit: d12e2be1999ad194d43f15b592a5cdf49ca54314 https://github.com/xwiki/xwiki-dev-llm/commit/d12e2be1999ad194d43f15b592a5cd... Author: Michael Hamann <[email protected]> Date: 2026-10-01 (Thu, 01 Oct 2026) Changed paths: M xwiki/okf/processes/security-policy.md M xwiki/skills/xwiki-security-advisory/SKILL.md Log Message: ----------- [Misc] Refer to the Security Policy for the rule against a PoC in security advisories * xwiki-security-advisory, security-policy.md: the forum proposal was accepted and the Security Policy requires it since October 2026 (revision 54.1) * xwiki-security-advisory: leave the template's "Don't provide reproduction steps" reminder out of the draft Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]> Commit: 4c2866a193d2e2656e886ca41e819e9b64431e46 https://github.com/xwiki/xwiki-dev-llm/commit/4c2866a193d2e2656e886ca41e819e... Author: Vincent Massol <[email protected]> Date: 2026-10-01 (Thu, 01 Oct 2026) Changed paths: M xwiki/okf/processes/security-policy.md M xwiki/skills/xwiki-security-advisory/SKILL.md Log Message: ----------- Merge pull request #179 from michitux/security-advisory-versions-no-poc Improve the security advisory skill regarding versions, PoC, credits and API usage Compare: https://github.com/xwiki/xwiki-dev-llm/compare/30ea18f98f14...4c2866a193d2 To unsubscribe from these emails, change your notification settings at https://github.com/xwiki/xwiki-dev-llm/settings/notifications