Fluid Attacks refers to contributing developers as "authors." Specifically, they are the individuals who have committed changes to the code repositories of the groups under evaluation.
In Fluid Attacks' platform, you can see who the authors of your groups are, along with information related to them. You need only enter the group of your interest and go to its Authors section.
Know the Authors table
The Authors table shows, for the selected month, who has contributed to developing the system(s) to which the group is dedicated. It comprises five columns:
- Author: The author name and their email used to make the commits
- Groups contributed: The name of the group to which the author has contributed
- Commit: The author's first commit of the selected month
- Repository: The first repository to which the author contributed in the selected month
- Registration status: The person's current registration status:
- Registered: The person has registered to the platform
- Pending: The person has been sent an invitation to register to the platform but has not yet registered
If an invitation to register is due, group members with the User Manager role can see the Invite button, which they can use to
send an invitation.
Filter authors by month
Role required: User, Vulnerability Manager or User Manager
To see the list of group authors in a specific month, click on the date at the top left to open a menu that includes the current month and the previous eleven months.
Filter Authors table by row data
Role required: User, Vulnerability Manager or User Manager
Additionally to filtering authors by month, you can filter them by email and author, group, and repository name. Access these options by clicking the Filters button.
Export Authors table
Role required: User, Vulnerability Manager or User Manager
You can download the list of authors as a CSV (comma-separated values) file by clicking on the Export button.
Search the Authors table
Role required: User, Vulnerability Manager or User Manager
You can use the search bar to filter the table in the Authors section. Just type in the content, and then only the rows whose information matches your search term(s) are shown.
Invite authors to sign up
Role required: User Manager
The notion of shared responsibility for secure development makes it important that all contributors to a repository be part of vulnerability management. That is why it is advisable that all software authors use Fluid Attacks' platform. If you are a User Manager, you can send registration invitations to contributors who do not have accounts on the platform yet.
The platform emails the author showing them the options to confirm and reject access. During the time it takes the author to respond to the registration invitation, their Registration status column on the platform shows a Pending status.
If the author rejects the invitation, the Registration status then reverts to Invite, whereas if the author accepts the invitation, the status changes to Registered.
Once authors register to the platform, they are also members, whose role you can manage to give them access to the platform functions they need.