Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Implement a Security page #438

Closed
dstufft opened this issue Mar 15, 2015 · 11 comments
Closed

Implement a Security page #438

dstufft opened this issue Mar 15, 2015 · 11 comments
Assignees
Labels
UX/UI design, user experience, user interface

Comments

@dstufft
Copy link
Member

dstufft commented Mar 15, 2015

We need a replacement for https://pypi.python.org/security.

@dstufft dstufft added this to the Become PyPI milestone Mar 15, 2015
@dstufft dstufft added the good first issue This issue is ideal for first-time contributors! label Apr 13, 2015
@trishankkarthik
Copy link
Contributor

Working on this!

@nlhkabu nlhkabu added the UX/UI design, user experience, user interface label Jul 16, 2015
@dstufft
Copy link
Member Author

dstufft commented May 14, 2016

A page has been added for this, but it's currently completely blank. Should just require filling out the template with content now.

@atodorov
Copy link
Contributor

@dstufft - should I use the same content as in https://pypi.python.org/security ?

Note: fixing this page also contributes to fixing the missing template titles exposed in #1203

@dstufft dstufft removed the good first issue This issue is ideal for first-time contributors! label May 24, 2016
@dstufft
Copy link
Member Author

dstufft commented May 24, 2016

Hey- So I (or someone) needs to actually come up with the correct content. The current security page is got a lot of incorrect information in it. Probably this one needs to just be done by me.

@dstufft dstufft self-assigned this May 24, 2016
@nlhkabu
Copy link
Contributor

nlhkabu commented Jun 27, 2016

I've just been looking over the docs and had a thought...

Is there any reason to have a separate security page that is different from https://warehouse.readthedocs.io/security/ ?

Maybe instead of having a standalone page, we can just link to this? That would mean we would only need to update the security content in one place.

@kezabelle
Copy link

Just to chime in unannounced, I find the RTD security page to be clearer than the current PyPI security page, because it offers just one course of clear action: email Donald and Richard.

Having used the security page on the current PyPI previously, and ultimately settling on emailing Donald, it was not without some reticence. I've outlined my thought process previously in a private email exchange with Donald (August 26, 2015), and looking back, there were a number of bullet points to get me to the point of making a decision vs. "just email these addresses"

As an addendum to @nlhkabu remark about linking, I'd subjectively prefer to see the security page on the PyPI site and linked to from the warehouse RTD -- trust is important, and causing a potential reporter to second guess where they've ended up isn't ideal, especially if they don't know that "warehouse" is ultimately synonymous with PyPI going forward. I don't know how much additional maintenance burden that may result in though.

@nlhkabu
Copy link
Contributor

nlhkabu commented Jul 1, 2016

As an addendum to @nlhkabu remark about linking, I'd subjectively prefer to see the security page on the PyPI site and linked to from the warehouse RTD... I don't know how much additional maintenance burden that may result in though.

I'm not too concerned about moving this content to a standalone page in Warehouse itself - the template is already there, so all we need to do is transfer the content.

My main concern with maintenance not duplicating the content, so linking to the Warehouse page from RTD seems like a good idea to me.

I agree that an end user is more likely to trust a 'page' on PyPI than the Warehouse docs.

@dstufft are you ok for me to go ahead with this?

@dstufft
Copy link
Member Author

dstufft commented Jul 1, 2016

@nlhkabu Using that content is probably roughly OK for now until I figure out a better policy that doesn't rely on me and Richard answering email. I agree it should be on PyPI itself not in our docs (which are less docs and more a collection of development notes). Should be easy to copy the data over and just delete that page from the Warehouse docs.

@pradyunsg
Copy link
Contributor

I'm putting my hand up for this!

@pradyunsg
Copy link
Contributor

This should be closed since #1985 is merged - correct?

@dstufft
Copy link
Member Author

dstufft commented May 14, 2017

Yup!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
UX/UI design, user experience, user interface
Projects
None yet
Development

No branches or pull requests

6 participants