*** subscope has quit IRC | 00:27 | |
*** salv-orl_ has joined #openstack-security | 00:42 | |
*** salv-orlando has quit IRC | 00:45 | |
*** austin987 has joined #openstack-security | 00:59 | |
*** salv-orl_ has quit IRC | 01:00 | |
*** markvoelker has joined #openstack-security | 01:09 | |
*** markvoelker has quit IRC | 01:13 | |
*** bpokorny has joined #openstack-security | 01:19 | |
*** ccneill has joined #openstack-security | 01:28 | |
*** elo has joined #openstack-security | 01:45 | |
*** winterisLeaving has quit IRC | 01:50 | |
*** winterIsLeaving has joined #openstack-security | 01:50 | |
*** bpokorny has quit IRC | 01:53 | |
openstackgerrit | Stanislaw Pitucha proposed openstack/anchor: Don't track autogenerated files https://review.openstack.org/282928 | 01:53 |
---|---|---|
*** ccneill has quit IRC | 01:59 | |
openstackgerrit | Stanislaw Pitucha proposed openstack/anchor: Anchor is source-only, so build common py2/py3 wheel https://review.openstack.org/282932 | 02:13 |
*** salv-orlando has joined #openstack-security | 02:38 | |
*** salv-orlando has quit IRC | 02:41 | |
*** salv-orlando has joined #openstack-security | 02:55 | |
*** salv-orlando has quit IRC | 03:01 | |
*** markvoelker has joined #openstack-security | 03:09 | |
*** markvoelker has quit IRC | 03:14 | |
*** yuanying has quit IRC | 03:20 | |
*** salv-orlando has joined #openstack-security | 03:57 | |
*** salv-orlando has quit IRC | 04:04 | |
*** yuanying has joined #openstack-security | 04:10 | |
*** diazjf has joined #openstack-security | 04:16 | |
*** bpokorny has joined #openstack-security | 04:22 | |
*** dave-mcc_ has joined #openstack-security | 04:24 | |
*** dave-mccowan has quit IRC | 04:25 | |
*** dave-mcc_ has quit IRC | 04:28 | |
*** bpokorny has quit IRC | 04:30 | |
*** dave-mccowan has joined #openstack-security | 04:40 | |
*** tkelsey has joined #openstack-security | 04:50 | |
*** tkelsey has quit IRC | 04:54 | |
*** markvoelker has joined #openstack-security | 05:10 | |
*** markvoelker has quit IRC | 05:15 | |
openstackgerrit | Eric Brown proposed openstack/bandit: Some use of ftplib is properly secure https://review.openstack.org/282952 | 05:32 |
*** diazjf has quit IRC | 05:33 | |
*** dave-mccowan has quit IRC | 05:37 | |
*** tonycc3 has joined #openstack-security | 05:42 | |
*** ccneill has joined #openstack-security | 05:55 | |
*** ccneill has quit IRC | 06:00 | |
*** tonycc3 has quit IRC | 06:06 | |
*** salv-orlando has joined #openstack-security | 06:11 | |
openstackgerrit | Eric Brown proposed openstack/bandit: Ignore all .coverage files and extensions https://review.openstack.org/282960 | 06:13 |
*** salv-orlando has quit IRC | 06:14 | |
*** salv-orlando has joined #openstack-security | 06:54 | |
*** salv-orlando has quit IRC | 07:02 | |
openstackgerrit | Andreas Jaeger proposed openstack/security-doc: DO NOT MERGE: testing bindep-based jobs https://review.openstack.org/282980 | 07:08 |
*** markvoelker has joined #openstack-security | 07:11 | |
*** markvoelker has quit IRC | 07:15 | |
*** 16WAACT9V has joined #openstack-security | 07:22 | |
*** liverpooler has joined #openstack-security | 07:22 | |
*** 32NAACSNA has joined #openstack-security | 07:22 | |
*** winterIsLeaving has quit IRC | 07:25 | |
*** salv-orlando has joined #openstack-security | 07:40 | |
*** subscope has joined #openstack-security | 07:51 | |
*** subscope has quit IRC | 07:51 | |
*** jamielennox is now known as jamielennox|away | 07:52 | |
*** jamielennox|away is now known as jamielennox | 08:02 | |
*** pcaruana has joined #openstack-security | 08:05 | |
*** subscope has joined #openstack-security | 08:07 | |
*** subscope has quit IRC | 08:17 | |
*** salv-orlando has quit IRC | 08:25 | |
*** subscope has joined #openstack-security | 08:26 | |
*** liverpoo1er has joined #openstack-security | 08:30 | |
*** 16WAACT9V has quit IRC | 08:31 | |
*** 32NAACSNA has quit IRC | 08:31 | |
*** liverpooler has quit IRC | 08:31 | |
*** liverpooler has joined #openstack-security | 08:31 | |
*** subscope has quit IRC | 08:40 | |
*** tkelsey has joined #openstack-security | 08:52 | |
*** tkelsey has quit IRC | 08:56 | |
*** subscope has joined #openstack-security | 09:00 | |
*** tkelsey has joined #openstack-security | 09:01 | |
*** markvoelker has joined #openstack-security | 09:12 | |
*** markvoelker has quit IRC | 09:16 | |
*** subscope has quit IRC | 09:25 | |
*** subscope has joined #openstack-security | 09:29 | |
*** tkelsey has quit IRC | 09:52 | |
*** tkelsey has joined #openstack-security | 10:22 | |
*** salv-orlando has joined #openstack-security | 10:26 | |
*** salv-orlando has quit IRC | 10:30 | |
*** winterIsLeaving has joined #openstack-security | 10:35 | |
*** liverpooler has quit IRC | 10:39 | |
openstackgerrit | Merged openstack/bandit: Ignore all .coverage files and extensions https://review.openstack.org/282960 | 10:39 |
*** elo has quit IRC | 10:41 | |
*** subscope has quit IRC | 10:57 | |
*** markvoelker has joined #openstack-security | 11:12 | |
*** markvoelker has quit IRC | 11:17 | |
*** subscope has joined #openstack-security | 11:30 | |
*** salv-orlando has joined #openstack-security | 11:33 | |
*** sigmavirus24_awa has quit IRC | 11:39 | |
*** z has quit IRC | 11:40 | |
*** kun_huang has quit IRC | 11:40 | |
*** fyxim has quit IRC | 11:40 | |
*** evand has quit IRC | 11:41 | |
*** evand has joined #openstack-security | 11:42 | |
*** salv-orlando has quit IRC | 11:43 | |
*** z has joined #openstack-security | 11:43 | |
*** fyxim has joined #openstack-security | 11:43 | |
*** kun_huang has joined #openstack-security | 11:43 | |
*** subscope has quit IRC | 11:45 | |
*** sigmavirus24_awa has joined #openstack-security | 11:45 | |
*** subscope has joined #openstack-security | 11:45 | |
openstackgerrit | Tim Kelsey proposed openstack/bandit: Legacy blacklist data is missing some expexted fields https://review.openstack.org/281937 | 12:27 |
*** daniela1 has joined #openstack-security | 12:37 | |
daniela1 | hola | 12:38 |
*** daniela1 has left #openstack-security | 12:39 | |
*** salv-orlando has joined #openstack-security | 12:40 | |
*** markvoelker has joined #openstack-security | 12:43 | |
*** salv-orlando has quit IRC | 12:44 | |
openstackgerrit | venkatamahesh proposed openstack/security-doc: Replace existing rst markups with new ones https://review.openstack.org/283063 | 12:46 |
*** markvoelker has quit IRC | 12:47 | |
*** winterIsLeaving has quit IRC | 12:48 | |
openstackgerrit | venkatamahesh proposed openstack/security-doc: Fix underline for heading https://review.openstack.org/283073 | 13:09 |
openstackgerrit | venkatamahesh proposed openstack/security-doc: Fix lowercase 's' in "Image Service" https://review.openstack.org/283075 | 13:15 |
*** markvoelker has joined #openstack-security | 13:29 | |
*** edmondsw has joined #openstack-security | 13:35 | |
*** salv-orlando has joined #openstack-security | 13:45 | |
*** salv-orlando has quit IRC | 13:52 | |
*** subscope has quit IRC | 13:56 | |
*** ninag has joined #openstack-security | 14:05 | |
*** localloop127 has joined #openstack-security | 14:07 | |
*** subscope has joined #openstack-security | 14:09 | |
*** dave-mccowan has joined #openstack-security | 14:14 | |
*** openstackgerrit has quit IRC | 14:17 | |
*** openstackgerrit has joined #openstack-security | 14:17 | |
*** salv-orlando has joined #openstack-security | 14:41 | |
*** cjschaef has joined #openstack-security | 14:50 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 14:59 | |
*** diazjf has joined #openstack-security | 14:59 | |
*** avarner has quit IRC | 15:07 | |
*** avarner has joined #openstack-security | 15:07 | |
*** avarner has quit IRC | 15:13 | |
*** tmcpeak has joined #openstack-security | 15:13 | |
*** diazjf1 has joined #openstack-security | 15:18 | |
*** diazjf has quit IRC | 15:21 | |
*** edtubill has joined #openstack-security | 15:24 | |
*** timkennedy has joined #openstack-security | 15:26 | |
*** jhfeng has joined #openstack-security | 15:28 | |
openstackgerrit | Travis McPeak proposed openstack/bandit: Making config optional https://review.openstack.org/278818 | 15:35 |
*** localloop127 has quit IRC | 15:41 | |
*** nkinder has joined #openstack-security | 15:50 | |
tmcpeak | sigmavirus24: got time to check this bad boy out? https://review.openstack.org/278818 | 15:51 |
sigmavirus24 | If it's so bad, do you expect anything other than a -1? :P | 15:52 |
tmcpeak | :# | 15:53 |
*** avarner has joined #openstack-security | 15:59 | |
*** Oku_OS has joined #openstack-security | 16:11 | |
*** browne has joined #openstack-security | 16:17 | |
openstackgerrit | Travis McPeak proposed openstack/bandit: Making config optional https://review.openstack.org/278818 | 16:21 |
tmcpeak | sigmavirus24: ^ :) | 16:22 |
*** pcaruana has quit IRC | 16:27 | |
*** ccneill has joined #openstack-security | 16:28 | |
openstackgerrit | Eric Brown proposed openstack/bandit: Some use of ftplib is properly secure https://review.openstack.org/282952 | 16:29 |
openstackgerrit | venkatamahesh proposed openstack/security-doc: Fix underline for heading https://review.openstack.org/283073 | 16:32 |
*** jmckind has joined #openstack-security | 16:32 | |
openstackgerrit | venkatamahesh proposed openstack/security-doc: Fix lowercase 's' in "Image service" https://review.openstack.org/283075 | 16:34 |
*** austin987 has quit IRC | 16:34 | |
*** localloop127 has joined #openstack-security | 16:44 | |
*** bpokorny has joined #openstack-security | 16:46 | |
*** austin987 has joined #openstack-security | 16:49 | |
*** bpokorny has quit IRC | 16:51 | |
*** bpokorny has joined #openstack-security | 16:51 | |
*** avarner has quit IRC | 16:56 | |
*** browne has quit IRC | 17:02 | |
*** mvaldes has joined #openstack-security | 17:09 | |
*** ccneill has quit IRC | 17:09 | |
*** uunsr has joined #openstack-security | 17:11 | |
*** ccneill has joined #openstack-security | 17:15 | |
*** ccneill has quit IRC | 17:17 | |
*** ccneill has joined #openstack-security | 17:18 | |
*** mvaldes1 has joined #openstack-security | 17:21 | |
tmcpeak | sigmavirus24, tkelsey: https://review.openstack.org/282952 | 17:21 |
*** mvaldes has quit IRC | 17:21 | |
*** mvaldes1 has quit IRC | 17:21 | |
tkelsey | kk | 17:22 |
*** mvaldes has joined #openstack-security | 17:23 | |
*** mvaldes1 has joined #openstack-security | 17:27 | |
*** mvaldes has quit IRC | 17:30 | |
*** avarner has joined #openstack-security | 17:32 | |
*** jmckind has quit IRC | 17:34 | |
*** subscope has quit IRC | 17:47 | |
*** mvaldes has joined #openstack-security | 17:50 | |
tmcpeak | sigmavirus24: ready for a +A if you're so inclined: https://review.openstack.org/#/c/278818/ | 17:53 |
*** mvaldes1 has quit IRC | 17:53 | |
tmcpeak | thanks buddy | 17:53 |
*** mvaldes has quit IRC | 17:56 | |
*** pdesai has joined #openstack-security | 17:57 | |
openstackgerrit | Merged openstack/bandit: Making config optional https://review.openstack.org/278818 | 17:57 |
*** sicarie has joined #openstack-security | 17:59 | |
*** shelleea007 has joined #openstack-security | 18:00 | |
shelleea007 | hello | 18:00 |
sicarie | hello | 18:00 |
pdesai | hi | 18:00 |
elmiko | hi | 18:00 |
sicarie | How’s everyone doing this week? | 18:02 |
pdesai | doing good, how about you? | 18:03 |
elmiko | not bad, finally starting to warm up a little here =) | 18:03 |
shelleea007 | super, how are you? | 18:03 |
sicarie | So, the first one we should talk about is this: https://bugs.launchpad.net/openstack-manuals/+bug/1543249 | 18:04 |
openstack | Launchpad bug 1543249 in openstack-manuals "Product endorsement in Passwords in Security Guide" [Low,Incomplete] - Assigned to Xing Chen (chen-xing) | 18:04 |
elmiko | sicarie: did you ever find an answer about using third party endorsements? | 18:05 |
sicarie | Yes, on the mailinglist loquacities (doc ptl) responded | 18:05 |
elmiko | ah, cool | 18:05 |
sicarie | I was looking for her answer so I could respond directly, but I can’t find it | 18:06 |
sicarie | Anyway, her statement was that we should remove the references | 18:06 |
*** browne has joined #openstack-security | 18:07 | |
elmiko | ah, too bad, i thought that rob's response on the bug was pretty strong | 18:07 |
sicarie | Discussion was taken to the ml | 18:07 |
elmiko | the regular -dev list? | 18:08 |
sicarie | So that was not brought up - I didn’t see it | 18:08 |
sicarie | http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-docs | 18:08 |
sicarie | Nope, the docs list | 18:08 |
sicarie | I’ll pursue that - thanks elmiko I missed that comment | 18:09 |
sicarie | Then there was one new bug: https://bugs.launchpad.net/openstack-manuals/+bug/1548302 | 18:10 |
openstack | Launchpad bug 1548302 in openstack-manuals "Use of :command: markup whereever necessary" [Undecided,New] - Assigned to venkatamahesh (venkatamaheshkotha) | 18:10 |
elmiko | in general, i get the advice about leaving out third party recommendations, but he made some good points about the sec doc. | 18:10 |
sicarie | +1 | 18:11 |
pdesai | we could change the guide and use command wherever appropriate, but lets divide the patch into at least chapter level | 18:12 |
*** jmckind has joined #openstack-security | 18:12 | |
sicarie | pdesai: +1 at the least chapter-level, preferably per-file? | 18:12 |
pdesai | per-file might end up in too many patches | 18:13 |
elmiko | as for the chapter-level break up, what about something like this then https://review.openstack.org/#/c/283063 ? | 18:13 |
pdesai | this is more coarse, it all depends on how quickly the whole patch gets merged, otherwise will endup rebasing mutliple times and unnecessary reviews | 18:15 |
sicarie | So personally I think this is too much at once, maybe have a file number requirement? | 18:15 |
elmiko | we might need to setup some sort of wiki page or something enumerating our sec-doc proceedures | 18:16 |
sicarie | +1 | 18:16 |
pdesai | +1 | 18:16 |
elmiko | shall i take an action to look into a wiki page for us? | 18:17 |
sicarie | I think it might be beneficial to outline the processes first - we can tack them onto the security wiki (or store them somewhere) until we know where to post them | 18:17 |
elmiko | maybe add a README to the root of our sec-doc folder in the manuals repo? | 18:19 |
sicarie | Yeah, something like that | 18:19 |
pdesai | +1 for README | 18:19 |
elmiko | then we can at least vote and argue over it ;) | 18:20 |
sicarie | heh | 18:20 |
pdesai | :) | 18:20 |
sicarie | elmiko: would you like to take a pass at that? | 18:20 |
elmiko | sicarie: sure, i'll toss out the first pitch | 18:21 |
sicarie | thanks! | 18:21 |
sicarie | So I’ll confirm the bug and post as wishlist | 18:22 |
elmiko | ok, so just to be clear, i'll make a patch for a README.rst in the security-guide subdir of the security-doc repo. does that sound good to everyone? | 18:22 |
sicarie | +1 | 18:22 |
pdesai | +1 | 18:22 |
elmiko | \o/ consensus | 18:23 |
sicarie | hehehe | 18:23 |
elmiko | (unless shelleea007 wants to be a contrarian) | 18:23 |
sicarie | hehe, i think she’s good - we’re multitasking something that came up | 18:24 |
shelleea007 | nope i'm good | 18:24 |
sicarie | Well, with that does anyone have something they’d like to discuss? | 18:24 |
sicarie | Any reviews needed? | 18:24 |
elmiko | just that one i linked, the others are much more focused | 18:25 |
sicarie | Sounds good, I’ll take a pass at that today | 18:27 |
elmiko | cool, i'll get some version of the readme up this week | 18:27 |
pdesai | cool | 18:27 |
sicarie | awesome, thanks everyone - see you next week! | 18:27 |
shelleea007 | se yall | 18:27 |
elmiko | take care | 18:27 |
pdesai | thank you everyone | 18:28 |
*** sicarie has quit IRC | 18:30 | |
*** salv-orl_ has joined #openstack-security | 18:42 | |
*** salv-orlando has quit IRC | 18:44 | |
*** shelleea007 has quit IRC | 18:47 | |
*** subscope has joined #openstack-security | 19:04 | |
*** elo has joined #openstack-security | 19:07 | |
*** ccneill has quit IRC | 19:13 | |
*** ninag has quit IRC | 19:27 | |
*** jmckind_ has joined #openstack-security | 19:28 | |
*** ninag has joined #openstack-security | 19:28 | |
*** jmckind_ has quit IRC | 19:29 | |
*** ninag_ has joined #openstack-security | 19:29 | |
*** ninag_ has quit IRC | 19:29 | |
*** ninag_ has joined #openstack-security | 19:29 | |
*** jmckind_ has joined #openstack-security | 19:30 | |
*** jmckind has quit IRC | 19:31 | |
*** ninag has quit IRC | 19:32 | |
*** ninag_ has quit IRC | 19:34 | |
*** ccneill has joined #openstack-security | 19:34 | |
*** ninag has joined #openstack-security | 19:34 | |
*** ninag has quit IRC | 19:39 | |
*** tkelsey has quit IRC | 19:44 | |
*** localloop127 has quit IRC | 19:54 | |
*** localloop127 has joined #openstack-security | 20:00 | |
*** dstanek has quit IRC | 20:20 | |
*** Daviey has quit IRC | 20:20 | |
*** bknudson_ has quit IRC | 20:20 | |
*** bknudson has joined #openstack-security | 20:20 | |
*** Daviey has joined #openstack-security | 20:20 | |
*** dstanek has joined #openstack-security | 20:21 | |
*** ninag has joined #openstack-security | 20:22 | |
*** bknudson has quit IRC | 20:26 | |
*** bknudson has joined #openstack-security | 20:36 | |
*** tmcpeak has quit IRC | 20:37 | |
*** tmcpeak has joined #openstack-security | 20:38 | |
*** openstackgerrit has quit IRC | 20:47 | |
*** openstackgerrit has joined #openstack-security | 20:47 | |
*** ian_ott has joined #openstack-security | 21:15 | |
*** jamielennox has quit IRC | 21:19 | |
*** jamielennox has joined #openstack-security | 21:20 | |
*** tkelsey has joined #openstack-security | 21:42 | |
*** tkelsey has quit IRC | 21:46 | |
*** edmondsw has quit IRC | 21:48 | |
*** ian_ott has quit IRC | 22:18 | |
*** localloop127 has quit IRC | 22:30 | |
*** avarner_ has joined #openstack-security | 22:32 | |
*** avarner has quit IRC | 22:32 | |
*** edtubill has quit IRC | 22:40 | |
*** ninag has quit IRC | 23:05 | |
*** salv-orl_ has quit IRC | 23:08 | |
*** salv-orlando has joined #openstack-security | 23:11 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 23:14 | |
*** avarner_ has quit IRC | 23:17 | |
*** avarner has joined #openstack-security | 23:17 | |
*** cjschaef has quit IRC | 23:29 | |
*** winterIsLeaving has joined #openstack-security | 23:31 | |
*** avarner has quit IRC | 23:34 | |
tmcpeak | browne: blacklists don't have help, huh? | 23:35 |
browne | tmcpeak: you mean each blacklist item? there is help | 23:37 |
tmcpeak | browne: there is? | 23:37 |
browne | http://docs-draft.openstack.org/52/282952/2/check/gate-bandit-docs/132319e//doc/build/html/blacklists/blacklist_calls.html | 23:38 |
tmcpeak | browne: wonder why its' not getting to here - http://docs.openstack.org/developer/bandit/plugins/index.html | 23:38 |
browne | its under a separate blacklist topic | 23:38 |
browne | http://docs-draft.openstack.org/52/282952/2/check/gate-bandit-docs/132319e//doc/build/html/blacklists/index.html | 23:38 |
tmcpeak | browne: oooh | 23:39 |
tmcpeak | ok, got it | 23:39 |
browne | but yes, i should probably update the help to note that a test was removed from the blacklist imports | 23:40 |
browne | since we now have a gap at B402 | 23:40 |
browne | also not sure whether we'll reuse these IDs ever | 23:40 |
browne | but since we haven't pushed a new version to PyPi yet, i guess we can re-number the IDs | 23:40 |
tmcpeak | browne: yeah | 23:41 |
tmcpeak | the reason I'm asking is I'm implementing links to the doc in the HTML report | 23:41 |
tmcpeak | our internal Bandit customer wants it | 23:41 |
browne | makes good sense | 23:42 |
browne | i think it was on my wishlist | 23:42 |
browne | another is how to resolve a particular issue | 23:42 |
tmcpeak | browne: yeah, they asked for that too | 23:42 |
tmcpeak | like what is the proper recommendation | 23:42 |
browne | haha | 23:43 |
browne | makes sense | 23:43 |
openstackgerrit | Eric Brown proposed openstack/bandit: Some use of ftplib is properly secure https://review.openstack.org/282952 | 23:45 |
*** pdesai has quit IRC | 23:48 | |
openstackgerrit | Travis McPeak proposed openstack/bandit: Removing duplicate Test ID in HTML report https://review.openstack.org/283310 | 23:49 |
openstackgerrit | Eric Brown proposed openstack/bandit: Some use of ftplib is properly secure https://review.openstack.org/282952 | 23:49 |
*** subscope has quit IRC | 23:50 | |
browne | tmcpeak: is there any way Bandit can interpret the value of an arg to a function? or would that require symbol-table goodness? | 23:54 |
tmcpeak | browne: yeah it needs symbol table | 23:54 |
browne | crap | 23:54 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!