*** sdake has quit IRC | 03:08 | |
*** sdake has joined #openstack-requirements | 03:08 | |
*** udesale has joined #openstack-requirements | 04:02 | |
*** hongbin has joined #openstack-requirements | 04:25 | |
*** hongbin has quit IRC | 04:53 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/requirements master: Updated from generate-constraints https://review.openstack.org/636091 | 06:14 |
---|---|---|
*** e0ne has joined #openstack-requirements | 07:23 | |
*** toabctl has joined #openstack-requirements | 07:26 | |
*** e0ne has quit IRC | 07:47 | |
*** e0ne has joined #openstack-requirements | 08:00 | |
*** e0ne has quit IRC | 08:05 | |
*** ccamacho has joined #openstack-requirements | 08:06 | |
*** hberaud|gone is now known as hberaud | 08:46 | |
*** finucannot is now known as stephenfin | 08:51 | |
*** tosky has joined #openstack-requirements | 08:54 | |
*** bnemec-pto has quit IRC | 08:57 | |
*** bnemec has joined #openstack-requirements | 08:59 | |
*** jpich has joined #openstack-requirements | 09:21 | |
*** dtantsur|afk is now known as dtantsur | 09:48 | |
*** hberaud is now known as hberaud|lunch | 11:44 | |
*** udesale has quit IRC | 12:05 | |
*** udesale has joined #openstack-requirements | 12:06 | |
*** hberaud|lunch is now known as hberaud | 12:10 | |
*** edmondsw has quit IRC | 13:46 | |
openstackgerrit | Terry Wilson proposed openstack/requirements stable/rocky: Update ovsdbapp to 0.12.3 in stable/rocky https://review.openstack.org/636133 | 14:22 |
openstackgerrit | Terry Wilson proposed openstack/requirements stable/queens: Update ovsdbapp to 0.10.3 in stable/queens https://review.openstack.org/636134 | 14:23 |
*** edmondsw has joined #openstack-requirements | 14:27 | |
openstackgerrit | sean mooney proposed openstack/requirements master: [DNM] test change https://review.openstack.org/636139 | 14:45 |
*** abhi89 has joined #openstack-requirements | 15:05 | |
*** snapiri has quit IRC | 15:08 | |
abhi89 | Hi All.. if i want to open a openstack bug whose fix would be updating version of a package in upper-constraints.txt or requirements file, then what project should i choose? | 15:12 |
abhi89 | this bug is not specific to any openstack service | 15:13 |
abhi89 | prometheanfire | 15:14 |
abhi89 | prometheanfire: ^^ | 15:14 |
abhi89 | there is vulnerability in python-requests package before version 2.20.0 (https://nvd.nist.gov/vuln/detail/CVE-2018-18074) | 15:37 |
abhi89 | in stein's upper-constraints.txt, we have requests===2.21.0. no worries here, we are above 2.20.0 | 15:38 |
abhi89 | but in ocata, pike & queens, the version is below 2.20 & the vulerability exists.. should we be updating the version requirement for python-requests package? | 15:39 |
abhi89 | tonyb: ^^ | 15:39 |
*** e0ne has joined #openstack-requirements | 16:04 | |
*** udesale has quit IRC | 16:15 | |
*** e0ne has quit IRC | 16:17 | |
prometheanfire | abhi89: reqs if it's requests | 16:17 |
prometheanfire | abhi89: the problem you'll run in to is that projects on those old versions may not work with newer versions of requests | 16:18 |
prometheanfire | abhi89: a ML thread may be good given it's impact | 16:18 |
*** e0ne has joined #openstack-requirements | 16:21 | |
*** e0ne has quit IRC | 16:26 | |
*** abhi89 has quit IRC | 16:28 | |
*** e0ne has joined #openstack-requirements | 16:36 | |
*** abhi89 has joined #openstack-requirements | 16:52 | |
abhi89 | prometheanfire: i don't see any reqs project while trying to raise a bug! | 16:53 |
abhi89 | prometheanfire: sorry, i didnot follow the ML thread thing.. what does it mean | 16:53 |
prometheanfire | abhi89: https://storyboard.openstack.org/#!/project/openstack/requirements | 16:54 |
prometheanfire | abhi89: mailing list thread | 16:54 |
prometheanfire | openstack-discuss | 16:54 |
abhi89 | ok | 16:54 |
abhi89 | prometheanfire, tonyb: created this story https://storyboard.openstack.org/#!/story/2004978. Please have a look sometime. | 17:06 |
prometheanfire | abhi89: 404? | 17:07 |
prometheanfire | abhi89: you mark it as 'security' or something? | 17:08 |
* prometheanfire should have perms there, being on the vmt | 17:09 | |
abhi89 | prometheanfire: strange! i have marked the story as private, but added you and tony as users who can view this story | 17:09 |
abhi89 | yes | 17:09 |
prometheanfire | ok, let me ping someone | 17:09 |
abhi89 | prometheanfire: ok let me know if you still cannot access it | 17:10 |
prometheanfire | abhi89: yep, asking a storyboard/vmt person | 17:10 |
abhi89 | ok | 17:10 |
prometheanfire | 11:13 < fungi > the vmt has to be explicitly added unless the url they followed to create the story included a url parameter to add us | 17:12 |
prometheanfire | 11:14 < fungi > by default, private stories are only visible to the account which created them | 17:12 |
prometheanfire | abhi89: ^ | 17:12 |
*** sdake has quit IRC | 17:12 | |
prometheanfire | fungi: could talk here I suppose | 17:13 |
fungi | yup | 17:14 |
fungi | also be aware suspected vulnerability report for the openstack/requirements project aren't officially overseen by the openstack vmt, so adding permission for a project-specific team to that story is appropriate | 17:15 |
fungi | (or for specific members of that project team, e.g. the ptl or a security reviewer liaison) | 17:15 |
prometheanfire | fungi: this seems like an upstream (public thing) anyway https://nvd.nist.gov/vuln/detail/CVE-2018-18074 | 17:15 |
prometheanfire | at least in this case | 17:15 |
fungi | yep, probably fine to switch that story to public | 17:16 |
*** sdake has joined #openstack-requirements | 17:16 | |
*** e0ne has quit IRC | 17:20 | |
abhi89 | ok, changing the visibility to public | 17:20 |
prometheanfire | don't see it yet | 17:26 |
abhi89 | prometheanfire: the tool wasn't letting me to change the visibility.. had to invalidate that story & create new one.. check this -> https://storyboard.openstack.org/#!/story/2004979 | 17:31 |
prometheanfire | ok, that may be a bug? fungi ^ | 17:33 |
prometheanfire | I can open that one | 17:33 |
fungi | um, to make it public you just edit the story properties and uncheck the private checkbox, then save | 17:33 |
fungi | how did you try to do it? did it give you an error? | 17:34 |
abhi89 | fungi: yeah, i just edited the story & unchecked the private checkbox.. the save option was not activated.. didnot allow me to save | 17:37 |
fungi | that's definitely odd | 17:39 |
fungi | i have certainly seen some flaky interaction with javascript validations not firing, so it's possible it didn't activate the save button because it didn't realize you had altered any of the form fields | 17:40 |
*** abhi89 has quit IRC | 17:55 | |
*** jpich has quit IRC | 17:57 | |
*** sdake has quit IRC | 18:01 | |
*** sdake has joined #openstack-requirements | 18:04 | |
*** dtantsur is now known as dtantsur|afk | 18:07 | |
*** sdake has quit IRC | 18:27 | |
*** sdake has joined #openstack-requirements | 18:30 | |
*** sdake has quit IRC | 18:32 | |
*** hberaud is now known as hberaud|gone | 18:49 | |
*** openstackgerrit has quit IRC | 18:51 | |
*** sdake has joined #openstack-requirements | 18:55 | |
*** sdake has quit IRC | 19:09 | |
*** e0ne has joined #openstack-requirements | 19:41 | |
*** e0ne has quit IRC | 20:08 | |
*** gouthamr has quit IRC | 20:38 | |
*** dmellado has quit IRC | 20:39 | |
*** e0ne has joined #openstack-requirements | 21:34 | |
*** gouthamr has joined #openstack-requirements | 21:39 | |
*** e0ne has quit IRC | 21:41 | |
*** dmellado has joined #openstack-requirements | 21:43 | |
*** sdake has joined #openstack-requirements | 22:20 | |
*** sdake has quit IRC | 22:51 | |
*** sdake has joined #openstack-requirements | 22:55 | |
*** sdake has quit IRC | 22:59 | |
*** sdake has joined #openstack-requirements | 23:07 | |
*** sdake has quit IRC | 23:31 | |
*** dtantsur has joined #openstack-requirements | 23:39 | |
*** stephenfin_ has joined #openstack-requirements | 23:45 | |
*** dtantsur|afk has quit IRC | 23:46 | |
*** TheJulia has quit IRC | 23:46 | |
*** stephenfin has quit IRC | 23:46 | |
*** coreycb has quit IRC | 23:46 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!