Thursday, 2016-04-28

*** rahulunair has quit IRC01:03
*** browne has joined #openstack-security01:21
*** agireud has quit IRC01:23
*** vinaypotluri has quit IRC01:30
*** jhfeng has joined #openstack-security01:39
*** austin987 has joined #openstack-security02:01
*** KarthikB has joined #openstack-security02:01
*** jhfeng has quit IRC02:14
*** browne has quit IRC02:14
*** mdong has quit IRC02:22
*** markvoelker has joined #openstack-security02:25
*** KarthikB has quit IRC02:38
*** chrisfkell has joined #openstack-security02:52
*** chrisfkell has quit IRC03:19
*** chrisfkell has joined #openstack-security03:22
*** DNegi has joined #openstack-security03:28
*** markvoelker has quit IRC03:34
*** markvoelker has joined #openstack-security03:35
*** markvoelker_ has joined #openstack-security03:39
*** markvoelker has quit IRC03:40
*** dave-mccowan has joined #openstack-security03:41
*** jass93 has quit IRC03:43
*** markvoelker_ has quit IRC03:44
*** markvoelker has joined #openstack-security03:45
*** markvoelker_ has joined #openstack-security03:48
*** markvoelker has quit IRC03:52
*** jass93 has joined #openstack-security03:57
*** markvoelker has joined #openstack-security03:59
*** markvoelker_ has quit IRC04:00
*** salv-orlando has joined #openstack-security04:00
*** jass93 has quit IRC04:02
*** jass93 has joined #openstack-security04:03
*** DNegi has quit IRC04:04
*** salv-orlando has quit IRC04:10
*** vinaypotluri has joined #openstack-security04:37
*** markvoelker has quit IRC04:49
*** ibravo has quit IRC05:00
*** markvoelker has joined #openstack-security05:43
*** markvoelker has quit IRC05:49
*** dave-mccowan has quit IRC05:52
*** chrisfkell has quit IRC06:03
*** markvoelker has joined #openstack-security06:38
*** markvoelker has quit IRC06:42
*** vinaypotluri has quit IRC06:50
*** ibravo has joined #openstack-security07:32
*** ibravo has quit IRC07:36
*** dmk0202 has joined #openstack-security08:10
*** panatl has quit IRC09:03
*** panatl has joined #openstack-security09:04
*** panatl has quit IRC09:11
*** panatl has joined #openstack-security09:11
*** panatl has quit IRC09:16
*** rcernin has joined #openstack-security09:44
*** markvoelker has joined #openstack-security10:14
*** markvoelker has quit IRC10:19
*** DNegi has joined #openstack-security10:29
*** markvoelker has joined #openstack-security11:08
*** markvoelker has quit IRC11:13
*** salv-orlando has joined #openstack-security11:33
*** DNegi has quit IRC11:49
*** salv-orlando has quit IRC11:50
*** markvoelker has joined #openstack-security11:56
*** markvoelker has quit IRC12:07
*** abstractj has quit IRC12:39
*** abstractj has joined #openstack-security12:39
*** salv-orlando has joined #openstack-security12:39
*** salv-orlando has quit IRC12:53
*** sdake has joined #openstack-security13:11
*** sdake_ has joined #openstack-security13:13
*** sdake has quit IRC13:17
*** ibravo has joined #openstack-security13:30
*** sdake_ has quit IRC13:36
*** tmcpeak has joined #openstack-security13:47
tmcpeaksigmavirus24_awa: pingy pingy13:47
*** tmcpeak has quit IRC13:53
*** tmcpeak1 has joined #openstack-security13:53
*** tmcpeak has joined #openstack-security13:54
*** tmcpeak1 has quit IRC13:57
*** browne has joined #openstack-security13:57
*** sdake has joined #openstack-security13:58
*** salv-orlando has joined #openstack-security13:58
*** markvoelker_ has joined #openstack-security14:11
*** dave-mccowan has joined #openstack-security14:12
*** edtubill has joined #openstack-security14:13
*** sigmavirus24_awa is now known as sigmavirus2414:15
sigmavirus24tmcpeak: what's up?14:15
*** salv-orlando has quit IRC14:21
*** cleong has joined #openstack-security14:22
tmcpeaksigmavirus24: yo - I was thinking about recommending projects EXCLUDE specifically tests they don't want to run14:22
tmcpeakand we'll take responsibility to run any new plugins against projects using Bandit, does that make sense?14:23
*** salv-orlando has joined #openstack-security14:23
sigmavirus24tmcpeak: i.e., we will test new plugins added to bandit against projects running bandit?14:23
tmcpeakyeah14:24
sigmavirus24tmcpeak: don't we already do that?14:26
tmcpeaksigmavirus24: we do, I'm asking if it's safe for us to use explicit exclude vs. include14:27
tmcpeakbased on your flake8 experience14:27
sigmavirus24so I forget how bandit has it implemented14:29
sigmavirus24but it's safer to use explicit exclude if you do it in the very simplest case14:30
tmcpeakok cool, was thinking so14:30
tmcpeakjust wanted to double check14:30
*** salv-orlando has quit IRC14:32
*** dave-mcc_ has joined #openstack-security14:35
*** nephilim1973 has quit IRC14:36
*** dave-mccowan has quit IRC14:38
*** nkinder has joined #openstack-security14:38
*** markvoelker_ has quit IRC14:40
*** robc_ has joined #openstack-security14:41
*** robc_ has left #openstack-security14:41
*** edtubill has quit IRC14:41
*** nkinder has quit IRC14:43
*** robc_ has joined #openstack-security14:46
*** robc_ has left #openstack-security14:46
*** hyakuhei has joined #openstack-security14:47
*** markvoelker has joined #openstack-security14:49
*** mdong has joined #openstack-security14:53
*** markvoelker has quit IRC14:54
*** markvoelker has joined #openstack-security14:56
*** bpokorny has joined #openstack-security14:57
*** salv-orlando has joined #openstack-security14:59
*** jamielennox|away is now known as jamielennox15:00
*** markvoelker_ has joined #openstack-security15:03
*** markvoelker has quit IRC15:05
*** salv-orlando has quit IRC15:06
*** dmk0202 has quit IRC15:06
*** salv-orlando has joined #openstack-security15:06
*** markvoelker_ has quit IRC15:08
*** sdake has quit IRC15:10
*** salv-orlando has quit IRC15:11
*** salv-orlando has joined #openstack-security15:13
*** sdake has joined #openstack-security15:16
*** salv-orlando has quit IRC15:20
*** dave-mcc_ has quit IRC15:20
*** dave-mccowan has joined #openstack-security15:25
*** austin987 has quit IRC15:31
*** dave-mccowan has quit IRC15:33
michaelxinhi15:37
michaelxinwelcome15:37
*** h00pz has joined #openstack-security15:38
* hyakuhei waves15:38
h00pzgday15:38
michaelxincool15:38
michaelxinit works15:38
michaelxinWelcome to the party15:38
*** bpokorny has quit IRC15:38
*** sdake has quit IRC15:41
*** h00pz has quit IRC15:42
*** jamielennox is now known as jamielennox|away15:42
*** austin987 has joined #openstack-security15:43
*** hyakuhei has quit IRC15:46
*** tmcpeak has quit IRC15:46
*** dave-mccowan has joined #openstack-security15:48
*** tmcpeak has joined #openstack-security15:51
*** hyakuhei has joined #openstack-security15:55
*** hyakuhei has quit IRC15:55
*** hyakuhei has joined #openstack-security15:55
*** ibravo has quit IRC15:56
*** bpokorny has joined #openstack-security15:56
*** nkinder has joined #openstack-security15:57
*** browne has quit IRC15:58
*** browne has joined #openstack-security16:00
*** rahulunair has joined #openstack-security16:02
*** jamielennox|away is now known as jamielennox16:03
*** sdake has joined #openstack-security16:04
*** jett has joined #openstack-security16:07
jettgood morning16:08
*** sdake has quit IRC16:08
*** sdake has joined #openstack-security16:09
openstackgerritOpenStack Proposal Bot proposed openstack/anchor: Updated from global requirements  https://review.openstack.org/30138616:10
*** h00pz has joined #openstack-security16:10
*** nkinder has quit IRC16:12
*** ibravo has joined #openstack-security16:15
*** jett has quit IRC16:21
tmcpeakbknudson: around?16:25
bknudsontmcpeak: yes16:25
tmcpeakhow do you add #nosec to a line that's too long already to support it16:25
bknudsonI'd split up the line.16:25
bknudsonfind a way to shorten the line16:25
tmcpeakahh ok cool16:25
tmcpeakgood point16:25
*** dave-mccowan has quit IRC16:32
*** ibravo has quit IRC16:33
*** h00pz has quit IRC16:33
*** browne has quit IRC16:37
*** tmcpeak has quit IRC16:37
*** hyakuhei has quit IRC16:38
*** jass93 has quit IRC16:38
*** jass93 has joined #openstack-security16:38
*** nkinder has joined #openstack-security16:40
*** nkinder has quit IRC16:47
*** jass93 has quit IRC16:49
*** browne has joined #openstack-security16:51
*** markvoelker has joined #openstack-security16:51
*** jamielennox is now known as jamielennox|away16:52
*** dave-mccowan has joined #openstack-security16:53
*** jass93 has joined #openstack-security16:53
*** tmcpeak has joined #openstack-security17:02
*** tmcpeak has quit IRC17:12
*** jhfeng has joined #openstack-security17:17
openstackgerritRahul U Nair proposed openstack/syntribos: Replacing opencafe requests with requests module  https://review.openstack.org/31060117:18
*** tmcpeak has joined #openstack-security17:20
*** sdake has quit IRC17:25
*** edmondsw has joined #openstack-security17:26
*** browne has quit IRC17:30
*** sdake has joined #openstack-security17:30
*** bpokorny has quit IRC17:32
*** tmcpeak has quit IRC17:32
*** markvoelker has quit IRC17:35
*** edmondsw has quit IRC17:37
*** jhfeng has quit IRC17:39
*** dave-mccowan has quit IRC17:40
*** sdake has quit IRC17:41
*** rcernin has quit IRC17:43
*** Guest54448 is now known as Vivek17:49
*** Vivek has joined #openstack-security17:49
*** chrisfkell has joined #openstack-security17:54
*** alejandrito has joined #openstack-security18:00
*** alejandrito_ has joined #openstack-security18:03
*** alejandrito__ has joined #openstack-security18:04
*** rcernin has joined #openstack-security18:17
*** alejandrito_ has quit IRC18:19
*** alejandrito has quit IRC18:19
*** alejandrito__ has quit IRC18:19
*** alejandrito has joined #openstack-security18:20
*** nkinder has joined #openstack-security18:22
*** chrisfkell has quit IRC18:24
*** jhfeng has joined #openstack-security18:28
*** chrisfkell has joined #openstack-security18:31
*** edmondsw has joined #openstack-security18:34
*** jamielennox|away is now known as jamielennox18:34
*** ibravo has joined #openstack-security18:40
*** browne has joined #openstack-security18:43
*** vinaypotluri has joined #openstack-security18:46
*** ibravo has quit IRC18:47
*** ibravo has joined #openstack-security18:48
*** rcernin has quit IRC18:50
*** Canaimero-henddr has joined #openstack-security18:51
*** Canaimero-henddr has quit IRC18:51
*** markvoelker has joined #openstack-security19:06
*** nkinder has quit IRC19:08
*** ibravo has quit IRC19:09
*** ibravo has joined #openstack-security19:09
*** jass93 has quit IRC19:09
*** browne has quit IRC19:11
*** ibravo has quit IRC19:13
*** jhfeng has quit IRC19:13
*** browne has joined #openstack-security19:15
*** jass93 has joined #openstack-security19:18
*** bpokorny has joined #openstack-security19:19
*** jhfeng has joined #openstack-security19:22
*** tmcpeak has joined #openstack-security19:23
*** edtubill has joined #openstack-security19:27
*** markvoelker has quit IRC19:27
*** tmcpeak has left #openstack-security19:29
*** markvoelker has joined #openstack-security19:29
*** rcernin has joined #openstack-security19:39
*** salv-orlando has joined #openstack-security19:39
*** salv-orlando has quit IRC19:41
*** sdake has joined #openstack-security19:44
*** zul has joined #openstack-security19:46
*** zul has quit IRC19:46
*** ibravo has joined #openstack-security19:47
*** salv-orl_ has joined #openstack-security19:50
*** jhfeng has quit IRC19:54
*** tmcpeak has joined #openstack-security19:55
*** hyakuhei has joined #openstack-security19:56
*** chrisfkell has quit IRC19:57
*** sdake has quit IRC20:00
*** salv-orl_ has quit IRC20:00
*** edtubill has quit IRC20:01
*** browne has quit IRC20:03
*** tmcpeak has left #openstack-security20:06
*** chrisfkell has joined #openstack-security20:07
*** jamielennox is now known as jamielennox|away20:09
*** zul has joined #openstack-security20:11
*** zul has quit IRC20:11
*** cleong has quit IRC20:12
*** tmcpeak1 has joined #openstack-security20:12
*** elo has joined #openstack-security20:18
*** ibravo has quit IRC20:19
*** tmcpeak1 has quit IRC20:28
*** ibravo has joined #openstack-security20:30
*** ibravo has quit IRC20:39
openstackgerritYasmine proposed openstack/syntribos: Removed assertions and modified failure keys  https://review.openstack.org/31091820:41
hyakuheiBYOK for castellan: https://review.openstack.org/#/c/310917/20:41
*** chrisfkell has quit IRC20:51
*** bpokorny has quit IRC20:51
*** hyakuhei has quit IRC20:51
openstackgerritYasmine proposed openstack/syntribos: Fixed pep8 whitespace issues.  https://review.openstack.org/31091821:02
*** tmcpeak has joined #openstack-security21:04
*** markvoelker has quit IRC21:07
*** jamielennox|away is now known as jamielennox21:08
*** bpokorny has joined #openstack-security21:08
*** tmcpeak has quit IRC21:09
openstackgerritYasmine proposed openstack/syntribos: Fixed pep8 whitespace issues - take two  https://review.openstack.org/31091821:10
*** tmcpeak has joined #openstack-security21:11
*** edmondsw has quit IRC21:11
*** elo has quit IRC21:14
*** salv-orlando has joined #openstack-security21:17
*** jamielennox is now known as jamielennox|away21:22
*** hyakuhei has joined #openstack-security21:26
*** hyakuhei has quit IRC21:26
*** hyakuhei has joined #openstack-security21:26
*** markvoelker has joined #openstack-security21:27
*** jass93 has quit IRC21:31
*** alejandrito has quit IRC21:34
*** salv-orlando has quit IRC21:38
*** tmcpeak has quit IRC21:39
*** tmcpeak has joined #openstack-security21:41
*** salv-orlando has joined #openstack-security21:41
tmcpeakhyakuhei: sorry man, I messed you up21:46
tmcpeakdouble checked now, current review is final answer21:46
hyakuheiWhy when 404 passes fine?21:47
tmcpeakhad written one thing and meant another.  We DO want to run the telnetlib import check but not subprocess (it's noisy)21:47
tmcpeakbecause it might not in the future21:47
tmcpeakif somebody uses subprocess (completely safely) we don't want Bandit to block their change21:47
tmcpeakwe could do the #nosec thing Brant was talking about though21:47
hyakuheik, that’s what nosec is for. I think you’re being a bit gunshy tbh. Bandit is pretty well established now21:47
tmcpeakyeah fair enough21:47
tmcpeakthen take off 404 from that project (and the comment)21:48
tmcpeakI just don't see the importing of subprocess itself as an issue21:48
tmcpeaksubprocess can be used completely safely21:48
hyakuheiNo it’s just something people should look closely at21:48
tmcpeakagreed21:48
tmcpeakbut gate should only fail for things that are real issues21:48
hyakuheiTeam can always turn off that check if it bugs them.21:49
tmcpeakcool, works for me21:49
hyakuheikk21:49
tmcpeakhyakuhei: you should remove B603 and B606 then tooo21:49
tmcpeakassuming those pass21:50
hyakuheicool21:50
*** rcernin has quit IRC21:53
*** salv-orlando has quit IRC21:55
*** bpokorny has quit IRC21:57
*** sigmavirus24 is now known as sigmavirus24_awa22:01
*** tmcpeak has quit IRC22:03
*** bpokorny has joined #openstack-security22:06
hyakuhei401 and 404 and 603 and 606 all removed from the skip list22:06
*** jass93 has joined #openstack-security22:10
*** amit213 has quit IRC22:37
*** amit213 has joined #openstack-security22:38
*** tmcpeak has joined #openstack-security22:41
*** bpokorny has quit IRC22:47
*** tmcpeak has quit IRC22:59
openstackgerritMerged openstack/anchor: Updated from global requirements  https://review.openstack.org/30138623:10
*** jass93 has quit IRC23:15
*** hyakuhei has quit IRC23:29
*** tmcpeak has joined #openstack-security23:31
*** markvoelker has quit IRC23:43
*** tmcpeak has quit IRC23:47

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!