)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"8d838bd061a1623cae022c6c5743cd7071abf8f9","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"ea45085b_95f4eef6","updated":"2026-09-01 22:24:32.000000000","message":"I think this is reasonable, thanks for championing!","commit_id":"45b0e1ae57d781bbc8d2d5e9bcc43698028e7aab"}],"goals/proposed/security-rst.rst":[{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"796b097f7eae96edcd525ea88e5c49b58fb367a5","unresolved":true,"context_lines":[{"line_number":61,"context_line":""},{"line_number":62,"context_line":"Status: YES"},{"line_number":63,"context_line":""},{"line_number":64,"context_line":"Is implemenation finalized?"},{"line_number":65,"context_line":"---------------------------"},{"line_number":66,"context_line":""},{"line_number":67,"context_line":"Status: YES"}],"source_content_type":"text/x-rst","patch_set":2,"id":"88116a62_cb844373","line":64,"range":{"start_line":64,"start_character":3,"end_line":64,"end_character":16},"updated":"2026-08-31 07:35:34.000000000","message":"```suggestion\nIs the implementation finalized?\n```\nis this a typo in the template?","commit_id":"4fde279504e0d8b0186077f774a1efc9bac9f51c"},{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"c1758328a680849144962478492b2acceef24361","unresolved":false,"context_lines":[{"line_number":61,"context_line":""},{"line_number":62,"context_line":"Status: YES"},{"line_number":63,"context_line":""},{"line_number":64,"context_line":"Is implemenation finalized?"},{"line_number":65,"context_line":"---------------------------"},{"line_number":66,"context_line":""},{"line_number":67,"context_line":"Status: YES"}],"source_content_type":"text/x-rst","patch_set":2,"id":"97f39499_5f1856f6","line":64,"range":{"start_line":64,"start_character":3,"end_line":64,"end_character":16},"in_reply_to":"88116a62_cb844373","updated":"2026-09-01 17:28:28.000000000","message":"Done","commit_id":"4fde279504e0d8b0186077f774a1efc9bac9f51c"},{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"796b097f7eae96edcd525ea88e5c49b58fb367a5","unresolved":true,"context_lines":[{"line_number":82,"context_line":"   similar file conforming to the goal\u0027s expectations."},{"line_number":83,"context_line":""},{"line_number":84,"context_line":"#. Any official cookie-cutter templates for OpenStack include an example"},{"line_number":85,"context_line":"   SECURITY.rst file based on the text provided within this goal."},{"line_number":86,"context_line":""},{"line_number":87,"context_line":"Champion"},{"line_number":88,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"}],"source_content_type":"text/x-rst","patch_set":2,"id":"9a5757b7_3a5b6bdf","line":85,"updated":"2026-08-31 07:35:34.000000000","message":"just a note because I needed to look for this myself: https://opendev.org/explore/repos?q\u003dcookiecutter\u0026tab\u003d would likely be a good URL to look up these templates, as referenced from https://docs.opendev.org/opendev/infra-manual/latest/creators.html#choosing-the-right-cookiecutter-template. maybe not needed to be explicitly mentioned within this goal, but could be added in the etherpad as well","commit_id":"4fde279504e0d8b0186077f774a1efc9bac9f51c"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"8d838bd061a1623cae022c6c5743cd7071abf8f9","unresolved":true,"context_lines":[{"line_number":33,"context_line":"  ---------------"},{"line_number":34,"context_line":""},{"line_number":35,"context_line":"  See https://security.openstack.org/ for directions on reporting suspected"},{"line_number":36,"context_line":"  security vulnerabilities. There you will also find the list of OpenStack"},{"line_number":37,"context_line":"  Security Advisory publications, along with the community\u0027s official"},{"line_number":38,"context_line":"  vulnerability handling processes and secure development guidelines."},{"line_number":39,"context_line":""},{"line_number":40,"context_line":"If a deliverable repository\u0027s documentation is primarily in Markdown format"}],"source_content_type":"text/x-rst","patch_set":4,"id":"059653b7_272739b9","line":37,"range":{"start_line":36,"start_character":65,"end_line":37,"end_character":32},"updated":"2026-09-01 22:24:32.000000000","message":"and OSSNs?","commit_id":"45b0e1ae57d781bbc8d2d5e9bcc43698028e7aab"},{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"35480b2eff87cca030b764ca2ddb591046692b10","unresolved":true,"context_lines":[{"line_number":33,"context_line":"  ---------------"},{"line_number":34,"context_line":""},{"line_number":35,"context_line":"  See https://security.openstack.org/ for directions on reporting suspected"},{"line_number":36,"context_line":"  security vulnerabilities. There you will also find the list of OpenStack"},{"line_number":37,"context_line":"  Security Advisory publications, along with the community\u0027s official"},{"line_number":38,"context_line":"  vulnerability handling processes and secure development guidelines."},{"line_number":39,"context_line":""},{"line_number":40,"context_line":"If a deliverable repository\u0027s documentation is primarily in Markdown format"}],"source_content_type":"text/x-rst","patch_set":4,"id":"096d83c0_88a56874","line":37,"range":{"start_line":36,"start_character":65,"end_line":37,"end_character":32},"in_reply_to":"059653b7_272739b9","updated":"2026-09-01 23:12:33.000000000","message":"The audience for these files aren\u0027t even going to know what an OpenStack Security Note is, much less realize we even make a distinction. Also OSSNs are in the Security Guide not on the security.openstack.org site. I\u0027d like to keep this short and to the point.","commit_id":"45b0e1ae57d781bbc8d2d5e9bcc43698028e7aab"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"f44c1e5af3b5408424ed39055d2226757f97807e","unresolved":false,"context_lines":[{"line_number":33,"context_line":"  ---------------"},{"line_number":34,"context_line":""},{"line_number":35,"context_line":"  See https://security.openstack.org/ for directions on reporting suspected"},{"line_number":36,"context_line":"  security vulnerabilities. There you will also find the list of OpenStack"},{"line_number":37,"context_line":"  Security Advisory publications, along with the community\u0027s official"},{"line_number":38,"context_line":"  vulnerability handling processes and secure development guidelines."},{"line_number":39,"context_line":""},{"line_number":40,"context_line":"If a deliverable repository\u0027s documentation is primarily in Markdown format"}],"source_content_type":"text/x-rst","patch_set":4,"id":"f938b9da_1114fc73","line":37,"range":{"start_line":36,"start_character":65,"end_line":37,"end_character":32},"in_reply_to":"096d83c0_88a56874","updated":"2026-09-04 06:33:01.000000000","message":"sure; there\u0027s a link to OSSNs from security.openstack.org, and it redirects to a different site.. don\u0027t mind us not adding that here.","commit_id":"45b0e1ae57d781bbc8d2d5e9bcc43698028e7aab"},{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"4e073a18b665f362a24242b216c020ad2caed269","unresolved":false,"context_lines":[{"line_number":33,"context_line":"  ---------------"},{"line_number":34,"context_line":""},{"line_number":35,"context_line":"  See https://security.openstack.org/ for directions on reporting suspected"},{"line_number":36,"context_line":"  security vulnerabilities. There you will also find the list of OpenStack"},{"line_number":37,"context_line":"  Security Advisory publications, along with the community\u0027s official"},{"line_number":38,"context_line":"  vulnerability handling processes and secure development guidelines."},{"line_number":39,"context_line":""},{"line_number":40,"context_line":"If a deliverable repository\u0027s documentation is primarily in Markdown format"}],"source_content_type":"text/x-rst","patch_set":4,"id":"f521f0ae_8d3936b3","line":37,"range":{"start_line":36,"start_character":65,"end_line":37,"end_character":32},"in_reply_to":"f938b9da_1114fc73","updated":"2026-09-04 18:20:49.000000000","message":"Yes, my thought process was that people who know we have a separate thing called an OSSN will already be able to figure out where those are. People who don\u0027t are just going to be looking for a list of security advisories instead, and will discover we also have separate security notes once they visit the site.","commit_id":"45b0e1ae57d781bbc8d2d5e9bcc43698028e7aab"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"8d838bd061a1623cae022c6c5743cd7071abf8f9","unresolved":true,"context_lines":[{"line_number":42,"context_line":"``SECURITY`` or ``SECURITY.txt`` for projects documented entirely in plain"},{"line_number":43,"context_line":"text."},{"line_number":44,"context_line":""},{"line_number":45,"context_line":"While the convention on GitHub is to automatically link files named"},{"line_number":46,"context_line":"``SECURITY.md`` as a \"security policy\" most OpenStack projects write their"},{"line_number":47,"context_line":"documentation in reStructuredText, so a ``SECURITY.rst`` file is more"},{"line_number":48,"context_line":"consistent with the repository\u0027s existing ``CONTRIBUTING.rst``,"},{"line_number":49,"context_line":"``HACKING.rst``, ``README.rst``, and so on. Some projects on GitHub have"},{"line_number":50,"context_line":"already used ``SECURITY.rst`` to this purpose since years (e.g."},{"line_number":51,"context_line":"``joke2k/django-environ``), and if enough projects follow that convention then"},{"line_number":52,"context_line":"GitHub will eventually update their interface to detect it as well. However,"},{"line_number":53,"context_line":"OpenStack is not developed on GitHub, so we are free to choose the solution"},{"line_number":54,"context_line":"which makes the most sense for us."},{"line_number":55,"context_line":""},{"line_number":56,"context_line":"Projects which publish Python packages to PyPI should also amend their package"},{"line_number":57,"context_line":"metadata to include a ``Security`` link to ``https://security.openstack.org/``"}],"source_content_type":"text/x-rst","patch_set":4,"id":"77094618_df32d1b2","line":54,"range":{"start_line":45,"start_character":0,"end_line":54,"end_character":34},"updated":"2026-09-01 22:24:32.000000000","message":"what if, when adding this, we symlink this and get this use case covered too?","commit_id":"45b0e1ae57d781bbc8d2d5e9bcc43698028e7aab"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"f44c1e5af3b5408424ed39055d2226757f97807e","unresolved":true,"context_lines":[{"line_number":42,"context_line":"``SECURITY`` or ``SECURITY.txt`` for projects documented entirely in plain"},{"line_number":43,"context_line":"text."},{"line_number":44,"context_line":""},{"line_number":45,"context_line":"While the convention on GitHub is to automatically link files named"},{"line_number":46,"context_line":"``SECURITY.md`` as a \"security policy\" most OpenStack projects write their"},{"line_number":47,"context_line":"documentation in reStructuredText, so a ``SECURITY.rst`` file is more"},{"line_number":48,"context_line":"consistent with the repository\u0027s existing ``CONTRIBUTING.rst``,"},{"line_number":49,"context_line":"``HACKING.rst``, ``README.rst``, and so on. Some projects on GitHub have"},{"line_number":50,"context_line":"already used ``SECURITY.rst`` to this purpose since years (e.g."},{"line_number":51,"context_line":"``joke2k/django-environ``), and if enough projects follow that convention then"},{"line_number":52,"context_line":"GitHub will eventually update their interface to detect it as well. However,"},{"line_number":53,"context_line":"OpenStack is not developed on GitHub, so we are free to choose the solution"},{"line_number":54,"context_line":"which makes the most sense for us."},{"line_number":55,"context_line":""},{"line_number":56,"context_line":"Projects which publish Python packages to PyPI should also amend their package"},{"line_number":57,"context_line":"metadata to include a ``Security`` link to ``https://security.openstack.org/``"}],"source_content_type":"text/x-rst","patch_set":4,"id":"d9d485b8_32fd8146","line":54,"range":{"start_line":45,"start_character":0,"end_line":54,"end_character":34},"in_reply_to":"0c82649b_202a47d2","updated":"2026-09-04 06:33:01.000000000","message":"Then I\u0027m missing the intent of this paragraph about GitHub perhaps?\n\nYes, humans/LLMs should know what to do with SECURITY.rst when they see one, but GitHub, smh, doesn\u0027t want to populate the \"Security\" tab on our repos looking at this file. that tab across all our mirrored repos will display \"This project has not set up a SECURITY.md file yet\" despite having this file.\n\nSo, my suggestion is to just delete this GitHub concern since we won\u0027t fix it. Like any other file, SECURITY.rst will get mirrored and we\u0027d deal with the GitHub Security Tab weirdness separately, or not.","commit_id":"45b0e1ae57d781bbc8d2d5e9bcc43698028e7aab"},{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"35480b2eff87cca030b764ca2ddb591046692b10","unresolved":true,"context_lines":[{"line_number":42,"context_line":"``SECURITY`` or ``SECURITY.txt`` for projects documented entirely in plain"},{"line_number":43,"context_line":"text."},{"line_number":44,"context_line":""},{"line_number":45,"context_line":"While the convention on GitHub is to automatically link files named"},{"line_number":46,"context_line":"``SECURITY.md`` as a \"security policy\" most OpenStack projects write their"},{"line_number":47,"context_line":"documentation in reStructuredText, so a ``SECURITY.rst`` file is more"},{"line_number":48,"context_line":"consistent with the repository\u0027s existing ``CONTRIBUTING.rst``,"},{"line_number":49,"context_line":"``HACKING.rst``, ``README.rst``, and so on. Some projects on GitHub have"},{"line_number":50,"context_line":"already used ``SECURITY.rst`` to this purpose since years (e.g."},{"line_number":51,"context_line":"``joke2k/django-environ``), and if enough projects follow that convention then"},{"line_number":52,"context_line":"GitHub will eventually update their interface to detect it as well. However,"},{"line_number":53,"context_line":"OpenStack is not developed on GitHub, so we are free to choose the solution"},{"line_number":54,"context_line":"which makes the most sense for us."},{"line_number":55,"context_line":""},{"line_number":56,"context_line":"Projects which publish Python packages to PyPI should also amend their package"},{"line_number":57,"context_line":"metadata to include a ``Security`` link to ``https://security.openstack.org/``"}],"source_content_type":"text/x-rst","patch_set":4,"id":"0c82649b_202a47d2","line":54,"range":{"start_line":45,"start_character":0,"end_line":54,"end_character":34},"in_reply_to":"77094618_df32d1b2","updated":"2026-09-01 23:12:33.000000000","message":"We don\u0027t develop our software on GitHub so I don\u0027t know what use case you\u0027re wanting covered. Humans and LLMs are smart enough to know if they see a file in the directory called `SECURITY.rst` or `SECURITY.md` or `SECURITY.txt` or whatever, that it serves the same purpose. Tools should serve people, we don\u0027t serve them.\n\nBut in case you need another argument against it, symlinks in Git repositories are a bad idea, and an even worse idea if they\u0027re in repositories that someone might try to make Python packages out of, since those have no way to represent a symlink today.","commit_id":"45b0e1ae57d781bbc8d2d5e9bcc43698028e7aab"},{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"4e073a18b665f362a24242b216c020ad2caed269","unresolved":true,"context_lines":[{"line_number":42,"context_line":"``SECURITY`` or ``SECURITY.txt`` for projects documented entirely in plain"},{"line_number":43,"context_line":"text."},{"line_number":44,"context_line":""},{"line_number":45,"context_line":"While the convention on GitHub is to automatically link files named"},{"line_number":46,"context_line":"``SECURITY.md`` as a \"security policy\" most OpenStack projects write their"},{"line_number":47,"context_line":"documentation in reStructuredText, so a ``SECURITY.rst`` file is more"},{"line_number":48,"context_line":"consistent with the repository\u0027s existing ``CONTRIBUTING.rst``,"},{"line_number":49,"context_line":"``HACKING.rst``, ``README.rst``, and so on. Some projects on GitHub have"},{"line_number":50,"context_line":"already used ``SECURITY.rst`` to this purpose since years (e.g."},{"line_number":51,"context_line":"``joke2k/django-environ``), and if enough projects follow that convention then"},{"line_number":52,"context_line":"GitHub will eventually update their interface to detect it as well. However,"},{"line_number":53,"context_line":"OpenStack is not developed on GitHub, so we are free to choose the solution"},{"line_number":54,"context_line":"which makes the most sense for us."},{"line_number":55,"context_line":""},{"line_number":56,"context_line":"Projects which publish Python packages to PyPI should also amend their package"},{"line_number":57,"context_line":"metadata to include a ``Security`` link to ``https://security.openstack.org/``"}],"source_content_type":"text/x-rst","patch_set":4,"id":"811d3e00_a9259cd4","line":54,"range":{"start_line":45,"start_character":0,"end_line":54,"end_character":34},"in_reply_to":"d9d485b8_32fd8146","updated":"2026-09-04 18:20:49.000000000","message":"I\u0027m happy to remove that paragraph if it\u0027s confusing. My intent was to get ahead of the inevitable suggestions, either during review or after it\u0027s approved, to just use GitHub\u0027s markdown \"standard\" instead. What I was really looking for was a section like most specification templates have, where I could list rejected ideas and the rationale behind rejecting them.","commit_id":"45b0e1ae57d781bbc8d2d5e9bcc43698028e7aab"}]}
