*** winterIsLeaving has quit IRC | 00:02 | |
openstackgerrit | Stanislaw Pitucha proposed openstack/bandit: Fix detached head baseline https://review.openstack.org/263072 | 00:04 |
---|---|---|
*** salv-orl_ has joined #openstack-security | 00:06 | |
*** salv-orlando has quit IRC | 00:09 | |
*** markvoelker has joined #openstack-security | 00:12 | |
openstackgerrit | Stanislaw Pitucha proposed openstack/bandit: Fix output encoding in baseline https://review.openstack.org/263074 | 00:26 |
openstackgerrit | Stanislaw Pitucha proposed openstack/bandit: Display nice error when profile is not found https://review.openstack.org/263077 | 00:49 |
openstackgerrit | Stanislaw Pitucha proposed openstack/bandit: Display nice error when profile is not found https://review.openstack.org/263077 | 01:10 |
*** salv-orl_ has quit IRC | 01:11 | |
*** salv-orlando has joined #openstack-security | 01:12 | |
openstackgerrit | Stanislaw Pitucha proposed openstack/bandit: Use binary mode when reading files https://review.openstack.org/263092 | 02:43 |
openstackgerrit | Stanislaw Pitucha proposed openstack/bandit: Split lines only once per file https://review.openstack.org/263094 | 02:52 |
openstackgerrit | Stanislaw Pitucha proposed openstack/bandit: Faster loc https://review.openstack.org/263095 | 02:58 |
openstackgerrit | Stanislaw Pitucha proposed openstack/bandit: Correct code output on python3 https://review.openstack.org/263101 | 03:37 |
openstackgerrit | Stanislaw Pitucha proposed openstack/bandit: Fix comment about value returned https://review.openstack.org/263110 | 04:39 |
*** shohel has joined #openstack-security | 04:39 | |
*** salv-orl_ has joined #openstack-security | 05:07 | |
*** salv-orlando has quit IRC | 05:07 | |
openstackgerrit | Stanislaw Pitucha proposed openstack/bandit: Use == for str comparison https://review.openstack.org/263117 | 05:21 |
*** winterIsLeaving has joined #openstack-security | 05:26 | |
*** winterIsLeaving has quit IRC | 05:35 | |
*** markvoelker has quit IRC | 05:39 | |
openstackgerrit | Stanislaw Pitucha proposed openstack/bandit: WIP: precise #nosec placement https://review.openstack.org/263122 | 05:53 |
openstackgerrit | Stanislaw Pitucha proposed openstack/bandit: Split lines only once per file https://review.openstack.org/263094 | 05:59 |
*** salv-orlando has joined #openstack-security | 06:06 | |
*** salv-orl_ has quit IRC | 06:09 | |
*** markvoelker has joined #openstack-security | 06:40 | |
*** markvoelker has quit IRC | 06:45 | |
*** winterIsLeaving has joined #openstack-security | 06:47 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/263150 | 06:51 |
openstackgerrit | Merged openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/263150 | 07:04 |
*** winterIsLeaving has quit IRC | 07:05 | |
*** shohel has quit IRC | 07:14 | |
*** Mainus has joined #openstack-security | 07:32 | |
*** salv-orlando has quit IRC | 07:34 | |
*** salv-orlando has joined #openstack-security | 07:35 | |
*** Mainus has quit IRC | 07:37 | |
*** salv-orlando has quit IRC | 07:42 | |
*** salv-orlando has joined #openstack-security | 07:42 | |
*** Mainus has joined #openstack-security | 07:43 | |
*** Mainus has quit IRC | 07:46 | |
openstackgerrit | Merged openstack/bandit: Fix detached head baseline https://review.openstack.org/263072 | 08:14 |
openstackgerrit | Merged openstack/bandit: Fix comment about value returned https://review.openstack.org/263110 | 08:15 |
openstackgerrit | Eric Brown proposed openstack/bandit: Replace logger.warn with logger.warning https://review.openstack.org/263059 | 08:17 |
openstackgerrit | Eric Brown proposed openstack/bandit: use six.moves.builtins in python3 https://review.openstack.org/262497 | 08:17 |
*** salv-orlando has quit IRC | 08:34 | |
*** salv-orlando has joined #openstack-security | 08:35 | |
*** liverpooler has joined #openstack-security | 08:36 | |
*** Crysty has joined #openstack-security | 08:38 | |
*** shohel has joined #openstack-security | 08:39 | |
Crysty | Hy | 08:39 |
openstackgerrit | Stanislaw Pitucha proposed openstack/bandit: Use binary mode when reading files https://review.openstack.org/263092 | 08:41 |
*** markvoelker has joined #openstack-security | 08:41 | |
*** Crysty has quit IRC | 08:43 | |
*** markvoelker has quit IRC | 08:45 | |
*** agireud has quit IRC | 08:51 | |
*** agireud has joined #openstack-security | 09:31 | |
*** agireud has quit IRC | 09:39 | |
*** agireud has joined #openstack-security | 09:47 | |
*** goodygum has joined #openstack-security | 09:50 | |
*** openstackgerrit has quit IRC | 10:02 | |
*** openstackgerrit has joined #openstack-security | 10:02 | |
*** markvoelker has joined #openstack-security | 10:42 | |
*** markvoelker has quit IRC | 10:46 | |
*** shohel has quit IRC | 11:55 | |
*** salv-orl_ has joined #openstack-security | 12:06 | |
*** salv-orl_ has quit IRC | 12:07 | |
*** salv-orl_ has joined #openstack-security | 12:07 | |
*** salv-orlando has quit IRC | 12:09 | |
*** markvoelker has joined #openstack-security | 12:12 | |
*** markvoelker has quit IRC | 12:17 | |
*** zul has quit IRC | 12:47 | |
*** zul has joined #openstack-security | 12:47 | |
*** markvoelker has joined #openstack-security | 12:55 | |
*** dave-mccowan has joined #openstack-security | 13:08 | |
*** salv-orl_ has quit IRC | 13:13 | |
*** salv-orlando has joined #openstack-security | 13:14 | |
*** edmondsw has joined #openstack-security | 13:20 | |
*** elmiko has joined #openstack-security | 13:28 | |
openstackgerrit | Tim Kelsey proposed openstack/bandit: Putting plugin config in code https://review.openstack.org/263282 | 14:23 |
*** sigmavirus24_awa is now known as sigmavirus24 | 15:01 | |
*** timkennedy has joined #openstack-security | 15:14 | |
*** shakamunyi has quit IRC | 15:15 | |
*** barra204 has quit IRC | 15:15 | |
*** tmcpeak has joined #openstack-security | 15:28 | |
*** shakamunyi has joined #openstack-security | 15:29 | |
*** timkennedy1 has joined #openstack-security | 15:31 | |
*** nkinder has joined #openstack-security | 15:31 | |
*** timkennedy has quit IRC | 15:33 | |
*** timkennedy has joined #openstack-security | 15:37 | |
*** timkennedy2 has joined #openstack-security | 15:38 | |
*** shohel has joined #openstack-security | 15:39 | |
*** timkennedy1 has quit IRC | 15:40 | |
*** timkennedy1 has joined #openstack-security | 15:41 | |
*** timkennedy has quit IRC | 15:42 | |
*** timkennedy2 has quit IRC | 15:43 | |
*** liverpooler has quit IRC | 16:07 | |
openstackgerrit | Merged openstack/bandit: Correct code output on python3 https://review.openstack.org/263101 | 16:10 |
openstackgerrit | Merged openstack/bandit: Fix output encoding in baseline https://review.openstack.org/263074 | 16:14 |
*** ccneill has joined #openstack-security | 16:35 | |
openstackgerrit | Merged openstack/bandit: Display nice error when profile is not found https://review.openstack.org/263077 | 16:37 |
*** michaelx- has quit IRC | 16:39 | |
*** timkennedy has joined #openstack-security | 16:43 | |
sigmavirus24 | So sad it couldn't have been an angry error ^ | 16:45 |
*** timkennedy1 has quit IRC | 16:47 | |
elmiko | lol | 16:50 |
*** barra204 has joined #openstack-security | 16:51 | |
*** shakamunyi has quit IRC | 16:51 | |
tmcpeak | we used to have an angry error | 16:52 |
tmcpeak | I'm sure we'll get more, don't worry | 16:52 |
openstackgerrit | Michael Dong proposed openstack/syntribos: Test runner and test result class now use Issues https://review.openstack.org/256878 | 17:03 |
*** timkennedy1 has joined #openstack-security | 17:09 | |
*** timkennedy has quit IRC | 17:12 | |
openstackgerrit | Merged openstack/bandit: Use binary mode when reading files https://review.openstack.org/263092 | 17:15 |
*** ccneill has quit IRC | 17:24 | |
*** ccneill has joined #openstack-security | 17:25 | |
*** salv-orl_ has joined #openstack-security | 18:06 | |
*** salv-orl_ has quit IRC | 18:06 | |
*** salv-orl_ has joined #openstack-security | 18:07 | |
*** salv-orlando has quit IRC | 18:08 | |
*** openstackgerrit has quit IRC | 18:32 | |
*** openstackgerrit has joined #openstack-security | 18:32 | |
*** bpokorny has joined #openstack-security | 18:43 | |
openstackgerrit | Merged openstack/bandit: Use == for str comparison https://review.openstack.org/263117 | 19:14 |
*** ccneill has quit IRC | 19:23 | |
openstackgerrit | Merged openstack/bandit: Replace logger.warn with logger.warning https://review.openstack.org/263059 | 19:24 |
*** browne has joined #openstack-security | 19:25 | |
*** winterIsLeaving has joined #openstack-security | 19:28 | |
openstackgerrit | Travis McPeak proposed openstack/bandit: TEST BANDIT GATE - DO NOT MERGE https://review.openstack.org/263401 | 19:30 |
*** ccneill has joined #openstack-security | 19:33 | |
openstackgerrit | Merged openstack/bandit: use six.moves.builtins in python3 https://review.openstack.org/262497 | 19:45 |
*** shohel has quit IRC | 19:49 | |
openstackgerrit | Travis McPeak proposed openstack/bandit: TEST BANDIT GATE - DO NOT MERGE https://review.openstack.org/263401 | 19:52 |
*** winterIsLeaving has quit IRC | 20:03 | |
tmcpeak | elmiko: how you feel about Bandit baseline gate for Sahara? | 21:30 |
elmiko | tmcpeak: i haven't played with it enough yet, but i think once we get green on the bandit test we should probably start using it | 21:30 |
tmcpeak | we need a guinea pig, ermmm, target, ermm, beta customer, ermmm… one of those but less negative connotations ;) | 21:30 |
elmiko | haha | 21:31 |
elmiko | we could certainly start using it as a test, our gate is non-voting | 21:31 |
tmcpeak | we've got one for Bandit itself already | 21:31 |
tmcpeak | well, in this case you'd put it as part of your voting flake8 tests | 21:31 |
elmiko | but i have been trying to get the sahara code base cleaned up so that we get green on that gate | 21:31 |
elmiko | ah, interesting | 21:31 |
tmcpeak | we don't need green anymore | 21:31 |
tmcpeak | it would just make sure new issues aren't introduced | 21:31 |
elmiko | yea | 21:32 |
elmiko | i will bring it up at our next team meeting and see what the group thinks | 21:32 |
tmcpeak | ok cool, sounds good | 21:32 |
elmiko | sadly, i don't think i will be able to make it to the midcycle =( | 21:33 |
tmcpeak | elmiko: bummer! | 21:34 |
tmcpeak | we're going to miss you man | 21:34 |
elmiko | yea, i'm bummed too. i thought it was really productive in seattle :/ | 21:35 |
elmiko | not to mention fun ;) | 21:36 |
openstackgerrit | Stanislaw Pitucha proposed openstack/bandit: Faster loc https://review.openstack.org/263095 | 21:39 |
openstackgerrit | Stanislaw Pitucha proposed openstack/bandit: Split lines only once per file https://review.openstack.org/263094 | 21:39 |
*** timkennedy1 has quit IRC | 21:49 | |
openstackgerrit | Merged openstack/bandit: Faster loc https://review.openstack.org/263095 | 22:06 |
openstackgerrit | Merged openstack/bandit: Split lines only once per file https://review.openstack.org/263094 | 22:14 |
*** salv-orl_ has quit IRC | 22:15 | |
*** edmondsw has quit IRC | 23:17 | |
*** avarner has joined #openstack-security | 23:40 | |
avarner | Hi, does anyone have information about the bandit refactoring? | 23:40 |
chair6 | hi avarner .. the spec for it is at https://github.com/openstack/security-specs/blob/master/specs/mikata/bandit/config-change.rst | 23:44 |
chair6 | but essentially, we're working on a) removing the need for a configuration file and b) making it easier for projects to adopt bandit as a gate | 23:45 |
chair6 | a) is addressed by the spec above, and b) is addressed by the recent work around bandit-baseline which is worth a look | 23:45 |
avarner | chair6, thanks | 23:45 |
chair6 | tmcpeak or tkelsey are doing most of the work and could tell you more.. :) | 23:45 |
tmcpeak | yo | 23:46 |
tmcpeak | avarner: which part in particular are you curious about? | 23:46 |
chair6 | work is underway, there is at least one active review on the config stuff, and with the security midcycle next week there should be some good progress | 23:46 |
tmcpeak | ++ | 23:46 |
avarner | tmcpeak, I couldn't find any info about it, so that link should be enough | 23:46 |
*** sigmavirus24 is now known as sigmavirus24_awa | 23:46 | |
avarner | I'm working on adding bandit to glance_store right now, but I'll maybe wait until this refactor is done | 23:47 |
tmcpeak | avarner: ok cool, yeah basically what chair6 said - projects have expressed the config file as a pain point, so we're aiming to get rid of it | 23:47 |
avarner | https://review.openstack.org/#/c/263411/ | 23:47 |
tmcpeak | avarner: I think a bandit-baseline gate might be best for you | 23:47 |
tmcpeak | you don't need a separate config, you can just use severity + confidence filtering to start like we currently do | 23:47 |
avarner | ok | 23:48 |
tmcpeak | that will get you at least something, and then once we've implemented our new profiles you can add a few more tests | 23:48 |
avarner | Thanks, I'll try it | 23:48 |
tmcpeak | avarner: see "Bandit Baseline Gate" here: https://wiki.openstack.org/wiki/Security/Projects/Bandit | 23:48 |
tmcpeak | if you have any questions or problems let me know | 23:49 |
avarner | thanks, I may have some tomorrow. For now, good night :) | 23:50 |
*** yuanying has quit IRC | 23:50 | |
tmcpeak | sounds good! | 23:50 |
*** yuanying has joined #openstack-security | 23:51 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!