| *** salv-orlando has joined #openstack-security | 00:05 | |
| *** nkinder has joined #openstack-security | 00:09 | |
| *** salv-orlando has quit IRC | 00:12 | |
| *** edmondsw has joined #openstack-security | 00:16 | |
| *** edmondsw_ has joined #openstack-security | 00:16 | |
| *** edmondsw_ has quit IRC | 00:17 | |
| *** salv-orlando has joined #openstack-security | 00:21 | |
| *** salv-orlando has quit IRC | 00:27 | |
| *** localloop127 has joined #openstack-security | 00:39 | |
| *** localloop127 has quit IRC | 00:45 | |
| *** edmondsw has quit IRC | 00:47 | |
| openstackgerrit | Ian Cordasco proposed stackforge/bandit: Remove unnecessary code that should have been replaced by entry-points https://review.openstack.org/195367 | 00:49 |
|---|---|---|
| openstackgerrit | Ian Cordasco proposed stackforge/bandit: Remove unnecessary code that should have been replaced by entry-points https://review.openstack.org/195367 | 00:50 |
| *** nkinder has quit IRC | 00:53 | |
| openstackgerrit | Ian Cordasco proposed stackforge/bandit: Actually rely on entry-points for formatters https://review.openstack.org/195367 | 00:56 |
| sigmavirus24 | tmcpeak: ^ should take care of that second issue you mentioned =P | 00:56 |
| *** sigmavirus24 is now known as sigmavirus24_awa | 00:58 | |
| *** tmcpeak has quit IRC | 01:01 | |
| *** localloop127 has joined #openstack-security | 01:12 | |
| *** sdake has joined #openstack-security | 01:28 | |
| *** sdake_ has joined #openstack-security | 01:29 | |
| *** sdake has quit IRC | 01:33 | |
| *** dontalton has quit IRC | 01:56 | |
| *** bpokorny has quit IRC | 01:59 | |
| *** sdake has joined #openstack-security | 02:13 | |
| *** sdake_ has quit IRC | 02:17 | |
| *** salv-orl_ has joined #openstack-security | 02:29 | |
| *** nkinder has joined #openstack-security | 02:33 | |
| *** salv-orl_ has quit IRC | 02:34 | |
| *** dave-mccowan has quit IRC | 02:59 | |
| *** amit213 has quit IRC | 03:12 | |
| *** zul has quit IRC | 03:13 | |
| *** amit213 has joined #openstack-security | 03:13 | |
| *** zul has joined #openstack-security | 03:16 | |
| *** localloop127 has quit IRC | 03:28 | |
| *** dave-mccowan has joined #openstack-security | 03:37 | |
| *** dave-mcc_ has joined #openstack-security | 03:37 | |
| *** salv-orlando has joined #openstack-security | 04:41 | |
| *** salv-orlando has quit IRC | 04:47 | |
| *** markvoelker has quit IRC | 05:43 | |
| *** browne has quit IRC | 06:01 | |
| *** shohel has joined #openstack-security | 06:19 | |
| openstackgerrit | Emett Speer proposed openstack/security-doc: Conslidated many of the small sections. https://review.openstack.org/187092 | 06:30 |
| *** markvoelker has joined #openstack-security | 06:43 | |
| *** markvoelker has quit IRC | 06:49 | |
| *** salv-orlando has joined #openstack-security | 06:54 | |
| *** salv-orlando has quit IRC | 06:56 | |
| *** salv-orlando has joined #openstack-security | 06:56 | |
| *** alex_klimov has joined #openstack-security | 08:03 | |
| *** markvoelker has joined #openstack-security | 08:32 | |
| *** markvoelker has quit IRC | 08:37 | |
| *** salv-orl_ has joined #openstack-security | 08:53 | |
| *** salv-orlando has quit IRC | 08:57 | |
| *** salv-orl_ has quit IRC | 08:58 | |
| *** salv-orlando has joined #openstack-security | 09:51 | |
| *** salv-orl_ has joined #openstack-security | 09:56 | |
| *** salv-orlando has quit IRC | 09:58 | |
| *** salv-orl_ has quit IRC | 09:59 | |
| *** salv-orlando has joined #openstack-security | 09:59 | |
| *** salv-orl_ has joined #openstack-security | 10:01 | |
| *** inderjeet has joined #openstack-security | 10:02 | |
| *** salv-orlando has quit IRC | 10:03 | |
| *** nkinder has quit IRC | 10:03 | |
| *** nkinder has joined #openstack-security | 10:03 | |
| *** inderjeet has left #openstack-security | 10:04 | |
| *** edmondsw has joined #openstack-security | 10:06 | |
| *** edmondsw has quit IRC | 10:06 | |
| *** edmondsw has joined #openstack-security | 10:07 | |
| *** markvoelker has joined #openstack-security | 10:21 | |
| *** markvoelker has quit IRC | 10:25 | |
| *** nkinder has quit IRC | 10:28 | |
| *** nkinder has joined #openstack-security | 10:47 | |
| *** sdake has quit IRC | 10:50 | |
| openstackgerrit | Merged stackforge/anchor: Bio mode needs to be passed as bytes https://review.openstack.org/194903 | 10:54 |
| openstackgerrit | Merged stackforge/anchor: Make bio operations work with str and bytes https://review.openstack.org/194902 | 10:57 |
| openstackgerrit | Andreas Jaeger proposed openstack/security-doc: Conslidated many of the small sections. https://review.openstack.org/187092 | 11:11 |
| *** salv-orl_ has quit IRC | 11:14 | |
| *** markvoelker has joined #openstack-security | 11:37 | |
| *** markvoelker has quit IRC | 11:41 | |
| openstackgerrit | Merged stackforge/anchor: Use hex, not get_hex() in uuid https://review.openstack.org/194901 | 11:44 |
| openstackgerrit | Merged stackforge/anchor: Use the right class for open file https://review.openstack.org/194473 | 11:45 |
| *** salv-orlando has joined #openstack-security | 11:49 | |
| *** markvoelker has joined #openstack-security | 11:58 | |
| *** bknudson has joined #openstack-security | 12:19 | |
| openstackgerrit | Merged stackforge/anchor: Use range instead of xrange https://review.openstack.org/194887 | 12:39 |
| *** sdake has joined #openstack-security | 12:56 | |
| *** elo has joined #openstack-security | 13:10 | |
| *** salv-orl_ has joined #openstack-security | 13:27 | |
| *** salv-orlando has quit IRC | 13:31 | |
| *** JAHoagie has joined #openstack-security | 13:41 | |
| *** tmcpeak has joined #openstack-security | 13:41 | |
| *** janonymous_ has joined #openstack-security | 13:42 | |
| *** JAHoagie has quit IRC | 13:45 | |
| *** JAHoagie has joined #openstack-security | 13:45 | |
| tmcpeak | sigmavirus24: ahh, sweet | 14:17 |
| *** JAHoagie has quit IRC | 14:20 | |
| *** localloop127 has joined #openstack-security | 14:21 | |
| *** localloo1 has joined #openstack-security | 14:26 | |
| *** localloop127 has quit IRC | 14:28 | |
| *** Deepika has joined #openstack-security | 14:34 | |
| *** Deepika has quit IRC | 14:38 | |
| *** deepika has joined #openstack-security | 14:38 | |
| *** voodookid has joined #openstack-security | 14:40 | |
| openstackgerrit | Merged openstack/security-doc: Conslidated many of the small sections. https://review.openstack.org/187092 | 14:44 |
| *** browne has joined #openstack-security | 14:59 | |
| *** shohel has quit IRC | 15:00 | |
| *** shohel has joined #openstack-security | 15:03 | |
| *** deepika has quit IRC | 15:03 | |
| *** edmondsw has quit IRC | 15:16 | |
| *** alex_klimov has quit IRC | 15:20 | |
| *** alex_klimov has joined #openstack-security | 15:20 | |
| *** bpokorny has joined #openstack-security | 15:22 | |
| *** edmondsw has joined #openstack-security | 15:25 | |
| *** hyakuhei has joined #openstack-security | 15:44 | |
| *** alex_klimov has quit IRC | 15:50 | |
| *** sdake_ has joined #openstack-security | 15:50 | |
| *** tkelsey has joined #openstack-security | 15:50 | |
| *** sdake has quit IRC | 15:54 | |
| *** localloo1 has quit IRC | 16:01 | |
| *** localloo1 has joined #openstack-security | 16:03 | |
| openstackgerrit | Merged stackforge/bandit: Actually rely on entry-points for formatters https://review.openstack.org/195367 | 16:25 |
| *** sdake_ is now known as sdake | 16:25 | |
| *** shohel1 has joined #openstack-security | 16:31 | |
| *** shohel has quit IRC | 16:34 | |
| *** shohel1 has quit IRC | 16:37 | |
| janonymous_ | Hi , | 16:47 |
| janonymous_ | Could someone help me on how to add bandit support | 16:48 |
| tmcpeak | janonymous_: you'll want to follow the instructions on this page: https://wiki.openstack.org/wiki/Security/Projects/Bandit under the section "Gate Testing with Bandit" | 16:49 |
| janonymous_ | To start with commits: 1) after adding in test-requirement.txt i hve to make a yaml file | 16:51 |
| tmcpeak | janonymous_: yep, you can refer to the Keystone example to see what it should look like | 16:52 |
| janonymous_ | tmcpeak : what are the dependencies of bandit | 16:56 |
| tmcpeak | janonymous_ they're listed in the requirements file of Bandit | 16:57 |
| janonymous_ | just wanted to ask that listing bandit in requirements will add all it's dependencies .. ryt ? | 17:00 |
| *** deepika has joined #openstack-security | 17:01 | |
| tmcpeak | yes | 17:01 |
| *** jian5397 has joined #openstack-security | 17:01 | |
| *** jian5397 is now known as michaelxin | 17:01 | |
| *** shohel has joined #openstack-security | 17:05 | |
| *** sdake_ has joined #openstack-security | 17:20 | |
| *** sdake has quit IRC | 17:24 | |
| *** sdake_ is now known as sdake | 17:29 | |
| *** jhfeng has joined #openstack-security | 17:39 | |
| *** localloo1 has quit IRC | 17:43 | |
| *** localloo1 has joined #openstack-security | 17:46 | |
| elmiko | sicarie: i don't think i'll make it after the meeting, sick as a dog and need to get back to bed =( | 17:53 |
| sicarie | elmiko: no worries, I'll follow up with you | 17:56 |
| elmiko | thanks | 17:56 |
| Daviey | tmcpeak: Breaking releases expose new sec' issues for projects, right? | 18:00 |
| browne | not so much breaking, just a new release of bandit that may be better or worse at finding issues | 18:01 |
| bknudson | new tests in bandit need to be opt-in | 18:01 |
| Daviey | bknudson: ^^ | 18:01 |
| browne | any new issue found would break keystone gate | 18:01 |
| browne | but i guess keystone would just fix it, so never mind | 18:01 |
| tmcpeak | so with profiles, new stuff in Bandit is opt in | 18:01 |
| Daviey | Which is why it might need to be capped release to start with, unless keystone is compliant with bandit git/1.0 already | 18:01 |
| tmcpeak | you don't get it unless you add it to your profile | 18:02 |
| tmcpeak | 1.0? | 18:02 |
| Daviey | the forthcoming release? | 18:02 |
| tmcpeak | oh, that will be a 0.11 :) | 18:02 |
| *** dontalton has joined #openstack-security | 18:02 | |
| tmcpeak | we're far from 1.0 | 18:02 |
| browne | tmcpeak: take for example hardcoded_password | 18:02 |
| Daviey | I wonder, should bandit have a non-voting check job against keystone? | 18:03 |
| browne | its an existing plugin, but doesn't get tested because wordlist/default-passwords is not shipped with the bandit binary | 18:03 |
| tmcpeak | it's not just that, it isn't included in the gate profiles | 18:03 |
| * Daviey needs to dash. o/ | 18:04 | |
| tmcpeak | Daviey: ok cool | 18:04 |
| bknudson | maybe -infra would be fine with bandit having tests for the other projects | 18:04 |
| tmcpeak | that's why we have profiles, so we can release things that aren't used in the gate | 18:04 |
| tmcpeak | bknudson: what do you mean? | 18:04 |
| bknudson | have a gate job in bandit that runs master against keystone master | 18:05 |
| browne | just saying that if hardcoded_password is in a project's profile, and we fix bandit to finally ship wordlist/default-passwords with it, then that project would potentially get a bandit issue raised | 18:05 |
| bknudson | and the rest of the projects | 18:05 |
| bknudson | that would be pretty neat | 18:06 |
| *** tmcpeak1 has joined #openstack-security | 18:06 | |
| *** fletcher_ has joined #openstack-security | 18:06 | |
| browne | that would be nice | 18:06 |
| fletcher_ | tmcpeak: halo | 18:07 |
| tmcpeak1 | fletcher_: hey' | 18:07 |
| tmcpeak1 | we're doing midcycle the first week in Sept and in Seattle | 18:07 |
| tmcpeak1 | can you make it? | 18:07 |
| tmcpeak1 | https://etherpad.openstack.org/p/security-liberty-midcycle | 18:08 |
| *** tmcpeak has quit IRC | 18:09 | |
| fletcher_ | Hmm, I think so | 18:10 |
| fletcher_ | only thing I can think is appsec | 18:10 |
| fletcher_ | lemme check real quick | 18:10 |
| fletcher_ | yah, i can make that | 18:11 |
| fletcher_ | i'll update etherpad | 18:11 |
| tmcpeak1 | fletcher_ awesome! | 18:11 |
| fletcher_ | thanks for looping me in | 18:12 |
| tmcpeak1 | for sure, looking forward to seeing you there | 18:13 |
| fletcher_ | yah, should be fun. we have a new office there too, so it'll be fun to see that as well | 18:15 |
| hyakuhei | good plan | 18:15 |
| *** bknudson has left #openstack-security | 18:29 | |
| *** bknudson has joined #openstack-security | 18:29 | |
| *** tkelsey has quit IRC | 18:35 | |
| *** jhfeng has quit IRC | 18:42 | |
| *** dontalton has quit IRC | 18:44 | |
| *** rbrooker has joined #openstack-security | 18:52 | |
| *** fletcher_ has quit IRC | 18:54 | |
| *** singlethink has joined #openstack-security | 19:09 | |
| *** singleth_ has joined #openstack-security | 19:10 | |
| *** bpokorny has quit IRC | 19:11 | |
| *** singlethink has quit IRC | 19:13 | |
| *** localloo1 is now known as localloop127 | 19:25 | |
| *** janonymous_ has quit IRC | 19:56 | |
| *** michaelxin has quit IRC | 20:01 | |
| *** jian5397 has joined #openstack-security | 20:02 | |
| *** jian5397 has quit IRC | 20:16 | |
| *** alex_klimov has joined #openstack-security | 20:17 | |
| *** jian5397 has joined #openstack-security | 20:18 | |
| *** sdake_ has joined #openstack-security | 20:24 | |
| *** sdake has quit IRC | 20:28 | |
| *** sdake_ is now known as sdake | 20:29 | |
| *** tmcpeak1 is now known as tmcpeak | 20:29 | |
| *** jian5397 has quit IRC | 21:32 | |
| *** localloop127 has quit IRC | 21:35 | |
| *** shohel has quit IRC | 21:39 | |
| *** jian5397 has joined #openstack-security | 21:42 | |
| *** singleth_ has quit IRC | 21:42 | |
| *** deepika has quit IRC | 21:53 | |
| *** jian5397 has quit IRC | 22:06 | |
| openstackgerrit | Jamie Finnigan proposed stackforge/bandit: Address multiline Str node lineno inaccuracies https://review.openstack.org/195761 | 22:10 |
| *** edmondsw has quit IRC | 22:27 | |
| *** dontalton has joined #openstack-security | 22:32 | |
| *** alex_klimov has quit IRC | 22:35 | |
| openstackgerrit | Michael Simo proposed openstack/security-doc: Fix malformed sentence in security-guide https://review.openstack.org/192880 | 22:41 |
| *** tmcpeak1 has joined #openstack-security | 22:45 | |
| openstackgerrit | Jamie Finnigan proposed stackforge/bandit: Address multiline node lineno inaccuracies https://review.openstack.org/195761 | 22:45 |
| *** dontalton has quit IRC | 22:45 | |
| *** tmcpeak has quit IRC | 22:47 | |
| openstackgerrit | Jamie Finnigan proposed stackforge/bandit: Address multiline node lineno inaccuracies https://review.openstack.org/195761 | 22:47 |
| openstackgerrit | Jamie Finnigan proposed stackforge/bandit: Address multiline node lineno inaccuracies https://review.openstack.org/195761 | 22:53 |
| *** sdake_ has joined #openstack-security | 23:00 | |
| *** sdake has quit IRC | 23:04 | |
| *** sdake has joined #openstack-security | 23:07 | |
| *** sdake_ has quit IRC | 23:11 | |
| *** voodookid has quit IRC | 23:11 | |
| *** jian5397 has joined #openstack-security | 23:18 | |
| *** rbrooker has quit IRC | 23:22 | |
| *** jian5397 has quit IRC | 23:23 | |
| *** markvoelker has quit IRC | 23:24 | |
| *** jian5397 has joined #openstack-security | 23:24 | |
| *** sicarie has quit IRC | 23:31 | |
| *** sdake has quit IRC | 23:54 | |
| *** sdake has joined #openstack-security | 23:55 | |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!