Re: ANN: Jenkins release artifacts uploads blockage on June 09, and a temporary downloads issue

2020-06-15 Thread Olivier Lamy
Awesome. Thanks a lot for the hard work! On Mon, 15 Jun 2020 at 23:10, Oleg Nenashev wrote: > Dear all, > > We have reset all plugin maintainer accounts, and we have reenabled plugin > uploads in the Repository Permission Updater. By now all upload permissions > should be restored, except a few

Re: Terminology Updates

2020-06-15 Thread Adrien Lecharpentier
I have to say that the music parallel from Angelique seems nice and has a lot of sense in my opinion. And the Jenkins butler is not that far from a music orchestrator as well. Le lun. 15 juin 2020 à 22:47, Daniel Beck a écrit : > > > > On 15. Jun 2020, at 22:39, Markus Winter wrote: > > > >

Re: Terminology Updates

2020-06-15 Thread Daniel Beck
> On 15. Jun 2020, at 22:39, Markus Winter wrote: > > Second the server is also just plain agent (more or less). For this we > could use the term "main" as the default label. That's what I proposed earlier in the thread as well. 'main' seems reasonable, but still has the connotation that

Re: Terminology Updates

2020-06-15 Thread Daniel Beck
> On 15. Jun 2020, at 16:00, Antonio Muñiz wrote: > > In spanish the term "Master" ("Maestro"), when used in isolation (no > "slave" in the context), has no negative connotations. If Jenkins (and before it, Hudson) had always used Master/Agent terminology, that would apply. But it didn't. I

Re: Terminology Updates

2020-06-15 Thread Markus Winter
I think currently we use the term master for 2 different things. First we have Jenkins orchestrating the builds, here the term controller probably fits best but also server seems to fit for me Second the server is also just plain agent (more or less). For this we could use the term "main"  as the

Re: ANN: Jenkins release artifacts uploads blockage on June 09, and a temporary downloads issue

2020-06-15 Thread Matt Sicker
No complaints about the lack of a DNSSEC record or other ways to avoid an initial MitM attack when connecting to jenkins.io for the first time. Or numerous other theoretical points of failure. It might be better to offer constructive advice rather than declaring everything broken. On Mon, Jun 15,

Re: ANN: Jenkins release artifacts uploads blockage on June 09, and a temporary downloads issue

2020-06-15 Thread Steve Springett
Security best practices should not be opt-in. I receive the manifest (daily) emails and did not see this topic. Many others likely did not either. Jenkins is viewed by many as Critical Cyber Infrastructure and plays an important role in the global software supply chain. That supply chain was

Re: ANN: Jenkins release artifacts uploads blockage on June 09, and a temporary downloads issue

2020-06-15 Thread Oleg Nenashev
Hi Steve, Duly noted. Note that we offered an alternate way for maintainers to get their password delivered if they are not fine with the current delivery method. In my message from Jub 12:* If anyone has concerns about such a method and wants to use alternate channels for encrypted password

Re: Terminology Updates

2020-06-15 Thread Matt Sicker
A master key is a particular type of universal key used for unlocking multiple different locks. In this case, the master key in Jenkins is used to unlock all the other encrypted data. It sort of makes sense. On Mon, Jun 15, 2020 at 10:04 AM Angélique Jard wrote: > > My preference goes to

Re: Terminology Updates

2020-06-15 Thread Angélique Jard
My preference goes to "controller", "server" make me think somehow to the hardware physical machine. "Coordinator" is fine also (in the link tools.ietf in previous post) but a bit hard to pronounce. As a non english native speaker (but french), I have some issue with "valet" and "majordomo"

Re: ANN: Jenkins release artifacts uploads blockage on June 09, and a temporary downloads issue

2020-06-15 Thread Steve Springett
"Technical debt" is not an excuse to reset plugin maintainers accounts and include a clear-text email containing their username AND password. That's insane. As a security professional I will not stand for that. I will no longer be maintaining Jenkins plugins and will attempt to find new

Re: accounts.jenkins.io can't login or use password reset

2020-06-15 Thread Oleg Nenashev
Uploads should be reenabled now: https://groups.google.com/d/msg/jenkinsci-dev/3UvrCTflXGk/gWT_tH7VAgAJ On Sunday, June 14, 2020 at 2:48:20 PM UTC+2, Oleg Nenashev wrote: > > Please see > https://groups.google.com/forum/m/#!topic/jenkinsci-dev/3UvrCTflXGk for > the status updates. Yes,

Re: Add New plugin request: kubesphere-token-auth-plugin

2020-06-15 Thread Jesse Glick
On Sun, Jun 14, 2020 at 11:52 PM SW C wrote: > In the upcoming 3.0,oauth authority authentication is realized. The > plugins of kubesphere-token-auth-plugin will complete the docking with oauth. I know nothing about Kubesphere but offhand it sounds like this could be a PR to

Re: Terminology Updates

2020-06-15 Thread Antonio Muñiz
In spanish the term "Master" ("Maestro"), when used in isolation (no "slave" in the context), has no negative connotations. Its main use is to describe someone very skilled in some matter (often used for artisans). I might be suffering of language bias, just wanted to give some "non english native

Plugin adoption request: Libvirt Slaves

2020-06-15 Thread Bastian Germann
Hi, I would like to adopt the Libvirt Slaves plugin [0] and opened a pull request [1] that fixes SECURITY-1014, which is open for 8 months now. The last time one of the listed maintainers touched the GitHub repo was in April 2014. Both my GitHub and Jenkins infrastructure usernames are bgermann.