By Marco Dings on 2020-05-19 10:42 in Production

Production Dept. Meeting
- May 19, 2020
1900 CEST, UTC+2  Event time TZ

 

DETAILS

Scheduled duration: 45min

Duration: 70min

Participants: Benjamin Trenkle (Team Leader), Carlos Cámara (Team Leader), , George Wilson (Release Lead 4.0) Hannes Papenberg (Team Leader),  Marco Dings (Department Coordinator), Nicola Galgano (Team Leader), Niels Braczek (Team Leader), Philip Walton (Team Leader), Robert Deutz (Team Leader), Tobias Zulauf (Release Lead 3.10),

Absent with notice: David Jardin (Team Leader), Harald Leithner (Release Lead 3.9), Mike Brandner (Team Leader), 

Absent without notice:Ilagnayeru Manickam (Team Leader), Puneet Kala (Team Leader)

Agenda Items & minutes

Department Coordinator (Marco Dings)

Talk Topics:

  1. There are several actions outstanding for the TL’s, please check the glip right hand pane and click on tasks

  2. With the absence of other candidates Llewellyn van der Merwe will be appointed assistant department coordinator (ADC). He will be added to glip and the jvp.

  3. We will be moving from glip tasks to github projects to have a more comprehensive closed project management for the DC (tasks, milestones and planning)

  4. There has been a serious data-breach incident, in its wake emphasis is put on existing and new rules for guarding privacy.

  5. All team leaders (TL) and assistant team leaders (ATL), department coordinator (DC)
    and assistant department coordinators (ADC) are requested/required to sign the joomla NDA ( joom.la/nda ).

  6. There is persistent confusion of the location of documents, typically their location should be named in the action or event. When in doubt navigate “the Joomla Production Department” google drive.


 

Joomla! Enhancement Development Team (Benjamin Trenkle)

Talk Topics:

  1. Testers needed for workflow


Joomla Accessibility Team (Carlos Cámara Mora)

Talk Topics:

  1. Some members of the group are able to bring testers but we need a test installation for them. I’m trying to find some way inside the project to make it happen.

  2. We are working on a testing guide for people interested in A11y but not familiar to it.

  3. This Saturday we are going to participate in GAAD Italy

  4. Discussing about resurrecting a11y-checker for TinyMCE

  5. We keep testing, discussing and working on issues for Backend template 


Security Strike Team (David Jardin)

Updates/Proposed Topics:

  1. The JSST is about to implement the Motion PROD2020/023 (Policy for Full Path Disclosure (FPD)) and will come up with an updated wording to make sure it does not cause confusion for the public.

  2. “Have I been Pwned” informed us of some of our mail accounts being affected by a latest breach. The accounts have been collected and the details have been coordinated with the DPO. Everyone affected has been notified by the DPO.

  3. JSST by means of David is involved in the data-breach investigation/discussion as mentioned in the board last week.

  4. The JSST worked and is still working on great general security improvements. Some of them landed in the public tracker in the last days / weeks. Would be great to get some tests and feedback on them:

    1. [3.x] Backport jQuery 3.5 security fixes

    2. [4.0] Introduce sitesecret / sitekey to Joomla 3.10 that replaces the secret value in 4.0

    3. [4.0] Add CssIdentifier Rule to future harden the CMS against XSS (and the backport for 3.10)

    4. [4.x] disable external entity loader for libxml

    5. [4.0] Add Cross-Origin-Opener-Policy to the HTTP Headers Plugin

    6. [4.0] Add Cross-Origin-Embedder-Policy header to the core htaccess and web.config.txt

    7. [4.0] Add the Report-To header to the http header config and allow to set the script-dynamic header


Automated Testing Team (Hannes Papenberg)

Talk Topics:

  1. All PRs should be covered by some form of tests and documentation...

Updates/Proposed Topics:

  1. [HL] Rebuild all docker container

  2. [HL] Fixed not working tests

  3. [HL] Implemented Yves PR to use uptodate chrome

  4. [HL] Implemented auto update and pull script for all containers and nodes


Release Leads (George Wilson, Tobias Zulauf, Harald Leithner)

* Releaselead 4.0 (George Wilson)

  1. Work continuing on workflows  (thanks to Harald and Benjamin!)

  2. Work continues to release beta at JAB

* Releaseleads 3.10 (Tobias Zulauf):

  1. There will be an article about 3.10 and the Update Checker in the upcoming JCM

  2. How to get the word out to extension developers about 3.10 and 4.0 as well as general communication where we as core developers get feedback on the things we do?

* Releaseleads 3.9 (Harald Leithner):

  1. Joomla! 3.9.19 is planned for June 02, 2020

  2. One important PR is 29117 created by Richard trying to fix the incomplete Database utf8mb4 conversion introduced in 3.9.17


Bug Squad (Nicola Galgano)

Talk Topics:

  1. Huge number of open issues recently js related


Software Architecture & Strategy Team (NIels Braczek)

Talk Topics:

  1. Nothing to report

Updates/Proposed Topics:

  1. “We will be moving from glip tasks to github projects” - PM research by research by NIels put on hold until further notice


CMS Release Team (Philip Walton)

Talk Topics:

  1. We are wanting a way to identify patches to test at PBF and BF@H and the best point to do this is when the patch is added. Please see the document for more details

  2. A better way of seeing what is being checked and tested in the CMS release group. At the moment its this spreadsheet 

Ideally, it's a hosted component that people can log into and run the tests then report on. They can edit their own entries against each release. Admins can see the results so that it's not on view to the world, unlike a like sheet. Marco has been helping. Wilco suggested it was hung on developers.joomla.org Need to consult with George

Updates/Proposed Topics:

  1. No release since the last meeting.

  2. Put out for a meeting and to find a deputy. The CMS release team documents subcommittee has been beavering away creating which is great. Jenn, Elisa, Tobias and I have been creating. Meeting 26th May 2020