mhaase's blog

Infrastructure Migration: Replacing SVN with Git

Over the past week, one of our engineers has been migrating our entire Version Control System (VCS) from a Subversion backend to a Git backend. We will be updating the website and our documentation to change the links and references from Subversion to Git. Please bear with us as we go through this, as there will undoubtedly be some broken links during the interim.

Effect on end users

For end users, this change won't have any direct effect. However, it will produce an indirect benefit for our end users because it gives us a lot more flexibility with release scheduling.

Open Source Incident Response

Beginning in Release 2.6, OpenFISMA includes an Incident Response module.

OpenFISMA Release 2.7

Endeavor Systems, Inc. is releasing OpenFISMA version 2.7.

For an overview of the new features that are included in this release, please view our Release Notes PDF (attached to this post).

We also have detailed release notes available that describes the individual tickets which went into this release.

Security Alert: XSS Vulnerability in 2.6

This is a security alert bulletin.

Affects: OpenFISMA 2.6.0 - 2.6.3

Fixed in: OpenFISMA 2.6.4

CVSS: (AV:N/AC:L/Au:N/C:C/I:C/A:N) 9.4

Description:

An XSS Vulnerability exists in the Incident module of OpenFISMA 2.6 (affecting 2.6.0 through 2.6.3). The vulnerability would allow an unauthenticated attacker to insert malicious active content (such as JavaScript) into another user's session. 

End of Life for IE6

With the latest release of OpenFISMA, we are officially announcing an end to support for the Internet Explorer 6 web browser.

We abandoned 'aesthetic' correctness in IE6 some time ago -- meaning that we only ensured that the application was functional in IE6, but not necessarily rendered correctly.

Even with that lower standard, though, troubleshooting IE6 bugs still absorbed hundreds of hours from our development schedule. Those hours could have been spent in more useful areas, such as improving usability or adding new functionality.

OpenFISMA 2.6

We tagged the release for OpenFISMA 2.6 this week. This is a big milestone!

At a high level, this release includes the following new features:

GOSCON Award

The OpenFISMA team is pleased to announce that the project won an award from the Government Open Source Conference (GOSCON) 2009 in the category of "Safe Computing Environment (Federal)". 

The GOSCON awards recognize government achievements in open source, and specifically recognized the Department of Education, the FDIC, and the USDA as partners in the OpenFISMA program.

The Joel Test

I'm a big fan of Joel Spolsky, author of the software blog, "Joel On Software". One of my favorite JOS articles is called "The Joel Test". This is a quick and dirty, 12 point test to see how good your development shop is. For fun, I ran down this list and evaluated it next to Endeavor's OpenFISMA team.

Syndicate content