Security auditing and response/status

Last update on: 2013-11-monthly

2013-03-monthly
The fundraising code base review is done. A MediaWiki security release, 1.20.3, was published on March 4. A review is underway for user metrics API.

2013-04-monthly
We released the MediaWiki 1.19.5 and 1.20.4 security releases on April 15th.

2013-05-monthly
We released MediaWiki 1.20.6/1.19.7 and provided security training for developers at the Amsterdam Hackathon.

2013-06-monthly
The team continued to respond to reported security issues, and gave security-oriented tech talks on emerging DoS techniques and using OWASP's ZAP tool for vulnerability scanning.

2013-07-monthly
The team continued to respond to reported security issues, and addressing outstanding bugs.

2013-08-monthly
The team responded to reported issues, and prepared for the next MediaWiki release, scheduled on September 3. We worked with Operations to enable HTTPS for user logins in most geographies.

2013-09-monthly
The team responded to reported issues, and released MediaWiki 1.21.2, 1.20.7 and 1.19.8 security releases to fix several issues in core and extensions.

2013-10-monthly
We responded to several issues reported in core and extensions. An emergency password reset was put into place to address a private data security issue.

2013-11-monthly
<section begin="2013-11-monthly"/>We released a security update to MediaWiki to fix a number of issues in core and extensions. Security reviews of Limn, GWTools and Flow extensions are in progress.<section end="2013-11-monthly"/>