Thursday, 2022-07-07

fungireminder: monthly sig meeting starts here in 5 minutes!14:55
fungi#startmeeting security15:00
opendevmeetMeeting started Thu Jul  7 15:00:49 2022 UTC and is due to finish in 60 minutes.  The chair is fungi. Information about MeetBot at http://wiki.debian.org/MeetBot.15:00
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.15:00
opendevmeetThe meeting name has been set to 'security'15:00
fungi#link https://etherpad.opendev.org/p/security-agenda Meeting Agenda15:01
fungiokay, let's get started15:03
fungi#topic Prior Actions15:03
fungifungi complete retirement process for security-analysis15:03
fungi#link     https://review.opendev.org/q/topic:retire-security-analysis Retirement changes for openstack/security-analysis15:03
fungithat's done, finally15:04
fungifungi add new volunteers to review groups15:04
fungi#link https://review.opendev.org/admin/groups/vmt,members VMT group in Gerrit15:04
fungi#link https://launchpad.net/~openstack-vuln-mgmt/+members VMT group in Launchpad15:04
fungi#link https://storyboard.openstack.org/#!/admin/team/1 VMT group in StoryBoard15:05
fungii added access for d34dh0r53 to the embargo coordination channel we use in irc and sent him a /invite, though dmendiza[m] doesn't seem to be identified with nickserv15:06
gagehugoo/15:06
fungialso it's dawned on me that i didn't add either of them to moderators/owners for the embargo-notice ml either15:07
fungi#action fungi add new volunteers to embargo-notice ml15:07
fungiand if you want to add openpgp keys to the security.o.o site, feel free to propose them in gerrit15:08
fungi#link     https://opendev.org/openstack/ossa/src/branch/master/doc/source/index.rst Feel free to propose changes adding OpenPGP keys15:08
fungii should probably also add them to the lp and gerrit groups for ossn/security-doc15:08
fungithose also look like they need some cleanup done for older participants who have moved on15:09
fungi#action fungi update ossn/security-doc members in gerrit and launchpad15:09
fungias for the last action item from last month, i haven't found time to get the ball rolling on that yet15:10
fungi#action fungi initiate openstack-discuss thread on the topic of xstatic packages and js dependency handling15:10
fungiquestions on any of those?15:10
fungilooks like no, so moving along...15:11
fungi#topic Pending Reviews15:11
fungi#link https://review.opendev.org/q/is:open+project:openstack/ossa Open change reviews for openstack/ossa15:11
fungiwe have one currently, to update prometheanfire's openpgp key to a newer expiration15:12
fungii've already +2'd it, but since we have more reviewers now i figured i'd let someone else approve15:12
fungigagehugo: d34dh0r53: dmendiza[m]: can one of you please take a look at https://review.opendev.org/846007 and approve if you think it looks okay?15:13
gagehugosure15:14
fungithere don't seem to be any open reviews for the security-doc repo at the moment15:14
fungithanks gagehugo!15:16
fungi#topic Public Bug Reports15:16
fungi#link https://bugs.launchpad.net/ossa/+bugs?field.information_type%3Alist=PUBLIC&field.information_type%3Alist=PUBLICSECURITY Public bug reports for OSSA15:17
fungithat query url specifically filters to just the public ones, mainly for the benefit of vmt members who also end up seeing the private ones listed by default15:17
fungiunfortunately, lp doesn't make it apparent which is which when you're just looking at a list of bugs15:18
fungii didn't have any new ones to call out specifically this month, but remember that anyone can help confirm and resolve those, doesn't have to be people on the vmt15:19
fungithe list is currently down to 6, which is really great, but lower would of course be even better!15:19
fungi2/3 of them are for neutron, so that's an opportunity for someone with network interest to pitch in15:20
fungiany comments before we move on?15:21
fungi#topic Anything else?15:21
funginow's your opportunity to bring up anything security-related you like15:22
fungiif nobody has anything, i'll wrap up the meeting in 5 minutes15:22
opendevreviewMerged openstack/ossa master: update Matthew Thode's gpg key  https://review.opendev.org/c/openstack/ossa/+/84600715:24
fungithanks everyone! next meeting will be at 15:00 utc on thursday august 415:28
fungifeel free to follow up in here or on the openstack-discuss ml if anyone has anything else in the meantime15:28
fungi#endmeeting15:28
opendevmeetMeeting ended Thu Jul  7 15:28:48 2022 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)15:28
opendevmeetMinutes:        https://meetings.opendev.org/meetings/security/2022/security.2022-07-07-15.00.html15:28
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/security/2022/security.2022-07-07-15.00.txt15:28
opendevmeetLog:            https://meetings.opendev.org/meetings/security/2022/security.2022-07-07-15.00.log.html15:28

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!