Hello everyone!
I am requesting membership for ~ubuntu-security. The details requested in the spec are provided below:
Team Membership
I am currently a member of the following teams:
- Canonical: Joined on 2024-05-20
- Canonical Security Team: 2024-05-20
- Ubuntu Security Apprentices: 2024-05-20
Verified Identify
My identity was verified through the general Canonical employee onboarding process, which includes a background check, and verification of my government issued identity documentation. Also, I have signed the Ubuntu Code of Conduct.
History of high-quality sponsored security updates
As a member of the Security Engineering team, I have patched CVE on several packages and published the corresponding USNs:
- matio: USN-6829-1
- Exim: USN-6881-1
- python-zipp: USN-6906-1
- ClickHouse: USN-6933-1
- DCMTK: USN-7010-1
- py7zr: USN-7030-1
- AsyncSSH: USN-7051-1
- libheif: USN-7082-1
Demonstrated understanding of required tools and systems
I have worked with UCT and QRT as a part of my CVE patching process, example merge requests are listed below:
- https://code.launchpad.net/~shishirsub10/ubuntu-cve-tracker/+git/ubuntu-cve-tracker/+merge/473380
- https://code.launchpad.net/~shishirsub10/ubuntu-cve-tracker/+git/ubuntu-cve-tracker/+merge/469079
- https://code.launchpad.net/~shishirsub10/qa-regression-testing/+git/qa-regression-testing/+merge/475675
I have updated package_info_overrides.json
so that new USNs can leverage this information, example merge requests are listed below:
- https://code.launchpad.net/~shishirsub10/ubuntu-cve-tracker/+git/ubuntu-cve-tracker/+merge/475671
- https://code.launchpad.net/~shishirsub10/ubuntu-cve-tracker/+git/ubuntu-cve-tracker/+merge/473705
Demonstrated understanding of the responsibility of ~ubuntu-security membership
I am following credentials best practices, my disk is fully encrypted, and have 2FA enabled for all accounts.
Thank you for your time!!