| *** hongbin has quit IRC | 00:04 | |
| *** xin9972 has quit IRC | 00:38 | |
| *** browne has quit IRC | 00:56 | |
| *** jamielennox is now known as jamielennox|away | 01:02 | |
| *** jamielennox|away is now known as jamielennox | 01:17 | |
| *** mdong has quit IRC | 01:18 | |
| *** markvoelker has joined #openstack-security | 01:27 | |
| *** knangia has quit IRC | 02:40 | |
| *** xin9972 has joined #openstack-security | 03:13 | |
| *** jerrygb_ has quit IRC | 04:02 | |
| *** jerrygb has joined #openstack-security | 04:09 | |
| *** jerrygb has quit IRC | 04:10 | |
| *** xin9972 has quit IRC | 04:30 | |
| *** diazjf has joined #openstack-security | 04:49 | |
| *** diazjf has quit IRC | 04:50 | |
| *** dikonoor has joined #openstack-security | 04:59 | |
| *** dikonoor has quit IRC | 05:09 | |
| *** jerrygb has joined #openstack-security | 05:11 | |
| *** jerrygb has quit IRC | 05:16 | |
| *** dikonoor has joined #openstack-security | 05:19 | |
| *** jerrygb has joined #openstack-security | 07:00 | |
| *** jerrygb has quit IRC | 07:06 | |
| *** tesseract has joined #openstack-security | 07:37 | |
| *** shohel has joined #openstack-security | 07:49 | |
| *** openstackgerrit has quit IRC | 08:03 | |
| *** pcaruana has joined #openstack-security | 08:45 | |
| *** jerrygb has joined #openstack-security | 09:02 | |
| *** jerrygb has quit IRC | 09:08 | |
| *** Serlex has joined #openstack-security | 09:10 | |
| *** jerrygb has joined #openstack-security | 11:04 | |
| *** jerrygb has quit IRC | 11:09 | |
| *** openstackgerrit has joined #openstack-security | 11:13 | |
| openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/424586 | 11:13 |
|---|---|---|
| openstackgerrit | Merged openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/424586 | 11:20 |
| *** dikonoo has joined #openstack-security | 11:22 | |
| *** dikonoor has quit IRC | 11:26 | |
| *** dikonoo has quit IRC | 12:03 | |
| *** gouthamr has joined #openstack-security | 12:13 | |
| *** catintheroof has joined #openstack-security | 12:16 | |
| *** shohel has quit IRC | 12:34 | |
| *** liverpooler has joined #openstack-security | 13:02 | |
| *** jerrygb has joined #openstack-security | 13:05 | |
| *** jerrygb has quit IRC | 13:10 | |
| *** AlexeyAbashkin has joined #openstack-security | 13:16 | |
| *** jmckind has joined #openstack-security | 13:18 | |
| *** dave-mccowan has joined #openstack-security | 13:18 | |
| *** strattao_ has joined #openstack-security | 13:26 | |
| *** gouthamr has quit IRC | 13:32 | |
| *** flvszch50 has joined #openstack-security | 13:35 | |
| *** gouthamr has joined #openstack-security | 14:15 | |
| *** pbourke has joined #openstack-security | 14:31 | |
| pbourke | hi, does anyone know once a CVE is patched how soon after packages are published to pypi? | 14:32 |
| *** jerrygb has joined #openstack-security | 14:44 | |
| *** xin9972 has joined #openstack-security | 14:47 | |
| *** jerrygb_ has joined #openstack-security | 14:47 | |
| *** gouthamr_ has joined #openstack-security | 14:49 | |
| *** jerrygb__ has joined #openstack-security | 14:49 | |
| *** gouthamr has quit IRC | 14:50 | |
| *** jerrygb has quit IRC | 14:51 | |
| *** gouthamr_ is now known as gouthamr | 14:51 | |
| *** jerrygb_ has quit IRC | 14:52 | |
| *** jerrygb has joined #openstack-security | 15:01 | |
| *** jerrygb__ has quit IRC | 15:05 | |
| *** hongbin has joined #openstack-security | 15:08 | |
| *** gouthamr has quit IRC | 15:13 | |
| *** markvoelker has quit IRC | 15:18 | |
| *** jmckind has quit IRC | 15:21 | |
| *** markvoelker has joined #openstack-security | 15:21 | |
| *** knangia has joined #openstack-security | 15:25 | |
| *** edtubill has joined #openstack-security | 15:36 | |
| *** dwyde has joined #openstack-security | 16:00 | |
| *** ccneill has joined #openstack-security | 16:04 | |
| openstackgerrit | Merged openstack/syntribos: Updated from global requirements https://review.openstack.org/424626 | 16:06 |
| *** jerrygb has quit IRC | 16:08 | |
| *** jerrygb has joined #openstack-security | 16:09 | |
| openstackgerrit | Merged openstack/syntribos: Removing payloads from the repo https://review.openstack.org/424315 | 16:10 |
| *** pcaruana has quit IRC | 16:16 | |
| sigmavirus | pbourke: you mean publicly disclosed? | 16:26 |
| pbourke | sigmavirus: yes, i.e. once its disclosed and patch merged in gerrit | 16:26 |
| sigmavirus | pbourke: the answer is *it depends on the team* | 16:27 |
| pbourke | makes sense | 16:27 |
| sigmavirus | Generally speaking, as long as it's merged there's no pressure to release | 16:27 |
| sigmavirus | Given that most CVEs occur in services, the answer is *never* | 16:27 |
| sigmavirus | Because the services aren't published to PyPI | 16:27 |
| pbourke | what about something like oslo | 16:27 |
| sigmavirus | oslo tends to release every week of a cycle before the non-client library freeze | 16:28 |
| sigmavirus | (which was last week) | 16:28 |
| sigmavirus | (the freeze took effect last week) | 16:29 |
| pbourke | guess Im just trying to feel out best practices here, a lot of places will build the services themselves so its easy to apply a patch and rebuild. Not so many will build every oslo lib listed in openstack/requirements | 16:29 |
| sigmavirus | pbourke: so the other thing is that a CVE would need to be backported to stable/ocata and a patch release requested for that | 16:31 |
| sigmavirus | but yeah, some places do that (openstack-ansible builds the world from scratch) | 16:31 |
| pbourke | thanks sigmavirus | 16:33 |
| sigmavirus | happy to help pbourke | 16:33 |
| *** sicarie has joined #openstack-security | 16:41 | |
| *** diazjf has joined #openstack-security | 16:45 | |
| *** mdong has joined #openstack-security | 16:54 | |
| *** browne has joined #openstack-security | 16:55 | |
| *** dwyde has quit IRC | 17:09 | |
| *** dwyde has joined #openstack-security | 17:10 | |
| *** dave-mccowan has quit IRC | 17:11 | |
| *** diazjf has quit IRC | 17:28 | |
| *** Serlex has quit IRC | 17:41 | |
| *** jmckind has joined #openstack-security | 17:43 | |
| *** dwyde has quit IRC | 17:49 | |
| *** jmckind_ has joined #openstack-security | 17:50 | |
| *** dave-mccowan has joined #openstack-security | 17:51 | |
| *** jmckind has quit IRC | 17:51 | |
| *** strattao_ has quit IRC | 18:01 | |
| *** strattao_ has joined #openstack-security | 18:02 | |
| openstackgerrit | Alexandra Settle proposed openstack/security-doc: Updating Object Storage data encryption content https://review.openstack.org/421375 | 18:14 |
| *** dwyde has joined #openstack-security | 18:18 | |
| *** chyka has joined #openstack-security | 18:20 | |
| *** dave-mccowan has quit IRC | 18:30 | |
| *** tesseract has quit IRC | 18:39 | |
| *** linuxac has joined #openstack-security | 18:43 | |
| *** linuxac has left #openstack-security | 18:43 | |
| *** diazjf has joined #openstack-security | 18:51 | |
| *** aber has joined #openstack-security | 18:55 | |
| aber | hallo | 18:55 |
| openstackgerrit | Merged openstack/security-doc: Updating Object Storage data encryption content https://review.openstack.org/421375 | 18:57 |
| *** dave-mccowan has joined #openstack-security | 18:58 | |
| *** aber has left #openstack-security | 18:59 | |
| openstackgerrit | Michael Glaser proposed openstack/security-doc: Networking architecture of Security guide implies direct DB conn. https://review.openstack.org/424801 | 19:02 |
| *** jmckind has joined #openstack-security | 19:24 | |
| *** jmckind_ has quit IRC | 19:27 | |
| *** jmckind has quit IRC | 19:28 | |
| *** datadog327 has joined #openstack-security | 19:28 | |
| *** jmckind_ has joined #openstack-security | 19:34 | |
| *** jmckind_ has quit IRC | 19:35 | |
| openstackgerrit | Merged openstack/syntribos: Updated pylint rules https://review.openstack.org/424330 | 19:37 |
| *** jmckind has joined #openstack-security | 19:38 | |
| openstackgerrit | Michael Glaser proposed openstack/security-doc: Networking architecture of Security guide implies direct DB conn. https://review.openstack.org/424801 | 19:48 |
| *** diazjf has quit IRC | 19:54 | |
| *** diazjf has joined #openstack-security | 19:57 | |
| *** jmckind has quit IRC | 20:02 | |
| *** jmckind has joined #openstack-security | 20:04 | |
| *** xin9972 has quit IRC | 20:05 | |
| *** jmckind has quit IRC | 20:08 | |
| *** jmckind has joined #openstack-security | 20:09 | |
| *** jmckind has quit IRC | 20:14 | |
| *** jmckind has joined #openstack-security | 20:14 | |
| *** jmckind_ has joined #openstack-security | 20:21 | |
| *** jmckind has quit IRC | 20:23 | |
| *** diazjf has quit IRC | 20:23 | |
| *** jmckind_ has quit IRC | 20:30 | |
| *** jmckind has joined #openstack-security | 20:37 | |
| *** ccneill has quit IRC | 20:39 | |
| *** ccneill has joined #openstack-security | 20:40 | |
| *** diazjf has joined #openstack-security | 20:40 | |
| *** ccneill has quit IRC | 20:48 | |
| *** diazjf has quit IRC | 20:55 | |
| *** jerrygb_ has joined #openstack-security | 21:01 | |
| *** jerrygb has quit IRC | 21:03 | |
| *** jerrygb_ has quit IRC | 21:04 | |
| *** dave-mccowan has quit IRC | 21:10 | |
| *** jmckind_ has joined #openstack-security | 21:23 | |
| *** jmckind has quit IRC | 21:25 | |
| *** catintheroof has quit IRC | 21:35 | |
| *** catintheroof has joined #openstack-security | 21:35 | |
| *** catintheroof has quit IRC | 21:35 | |
| *** jmckind has joined #openstack-security | 21:39 | |
| *** jmckind_ has quit IRC | 21:40 | |
| *** codfection has joined #openstack-security | 21:55 | |
| *** jmckind has quit IRC | 22:00 | |
| *** dwyde has quit IRC | 22:06 | |
| *** datadog327 has quit IRC | 22:15 | |
| *** xin9972 has joined #openstack-security | 22:33 | |
| *** xin9972 has quit IRC | 22:34 | |
| *** codfection has quit IRC | 22:51 | |
| *** strattao_ has quit IRC | 22:55 | |
| *** strattao_ has joined #openstack-security | 23:01 | |
| openstackgerrit | Michael Dong proposed openstack/syntribos: Added support for meta variable JSON files https://review.openstack.org/411415 | 23:09 |
| *** mdong has quit IRC | 23:11 | |
| *** mdong has joined #openstack-security | 23:11 | |
| openstackgerrit | Michael Dong proposed openstack/syntribos: Added support for meta variable JSON files https://review.openstack.org/411415 | 23:13 |
| *** edtubill has quit IRC | 23:15 | |
| *** strattao_ has quit IRC | 23:23 | |
| *** dave-mccowan has joined #openstack-security | 23:33 | |
| *** mdong has quit IRC | 23:42 | |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!