[dokuwiki] Re: DokuWiki Security Audit

  • From: Andreas Haerter <list+dokuwiki@xxxxxxxxxxxxxxxxxxx>
  • To: dokuwiki@xxxxxxxxxxxxx
  • Date: Fri, 23 Mar 2012 17:05:42 +0100

Hi,

On 22.03.2012 10:21, Andreas Gohr wrote:
> thanks for taking this into your hands.

No problem ;-).


> We careful need to plan such a funding campaign. Usually you also set
> up perks, eg. things a backer gets for giving a certain amount of
> money. We should think about what would be useful for companies here.
> Here are a few ideas:
> 
> 100EUR - backer's name is listed on dokuwiki.org/security_audit
> 500EUR - backer's name, link and company logo is mentioned in the newsletter
> 1000EUR - an invoice directly from Section1 about 1day of DokuWiki
> security audit (if Section1 agrees to this, as it would mean that
> they'd have to split up the project financially)
> 2000EUR - the audit results are shared with the backer right on
> arrival (I'd vote for holding back the results until we had some time
> to fix any vulnerabilities)
> 
> Well, you get the idea...

and it's great. I hope I get the time to think about ASAP and come up
with a reasonable plan (However: @all -> any further
comments/ideas/opinions are welcome). Shall I create a new site on
dokuwiki.org (e.g. <http://www.dokuwiki.org/devel:security_audit>)? We
could collect useful data there...

-- 
Andreas <http://blog.andreas-haerter.com>

O< ascii ribbon campaign - stop html mail - www.asciiribbon.org

Other related posts: