Tuesday, 2022-10-18

Tenguhello there07:38
Tengufungi: heya! fyi, I appear to be the (new) Security Liaison for TripleO. I'm starting reading things about Security-SIG and related, and am wondering if there's any specific ML I should subscribe?07:43
fungiTengu: none, we post to openstack-discuss with [security-sig] in the subject line11:17
fungiTengu: we also hold a meeting in here on the first thursday of every month, and we have a ptg session tomorrow if you want to join11:20
Tengufungi: ah, perfect, I don't have anything yet for tomorrow!11:42
TenguI'll add a new filter for security-sig as well.11:42
Tengufungi: tripleo is wanting to move to DPL, meaning we'll have to do some homework and proper communication. afaik there's also a page where the security liaison is mentioned. Is there something like a "what to do" and related? i.e. I don't really know *what* is expected from me :)11:45
Tenguah, just seeing the session tomorrow. 3pm UTC, in Diablo. perfect.11:46
fungiTengu: well, the room link is to meetpad so it's not really *in* the diablo zoom, but if you click the session on the ptg schedule it'll take you to the right place11:48
Tengufungi: ah, yeah, ok. is there some etherpad with some agenda btw?11:48
fungiyes, the etherpad in the etherpads list on the ptg site11:49
Tenguoh, didn't see the link at the top.11:49
Tengumeh.11:49
fungias for the liaison role, for repositories officially overseen by the vmt it's #6 at https://security.openstack.org/repos-overseen.html#requirements11:49
fungitripleo hasn't opted into official vmt oversight, but there's still a need for a primary point of escalation for security issues if tripleo's security review team11:51
fungiis otherwise unresponsive on them11:51
Tengusounds good. tripleo itself isn't just one repository. it's... well. "a huge pile of things".11:52
TenguI'll check with the current PTL if we want to opt in, what would be the expectations, what repositories would be affected and so on. I see there's python client repos, maybe python-tripleoclient might join the feast. maybe with tripleo-heat-templates.11:53
fungiright. tripleo could choose to opt some of its repositories into vmt oversight if it feels like asserting compliance with the list of requirements on that page i linked11:53
Tengu(and tripleo-ansible - that's becoming the "heart" of tripleo nowadays)11:53
Tengu'k. I don't want to make a revolution, but still... having some proper security management won't hurt, really.11:54
gagehugofungi: the security session is tomorrow at this time right?15:05
fungigagehugo: correct15:05
gagehugook cool15:06
fungii would have done it on thursday at our typical meeting time but there were too many conflicts15:06
gagehugoyeah thursdays are usually bad for me15:08
fungishould we also talk about rescheduling our monthly meetings?15:08
fungiour usual thursday time also conflicts with weekly tc meetings, which i normally try to attend when i'm not chairing ours15:09
gagehugoDon't do it on my behalf, but yeah if we did I wouldn't be opposed15:10
fungicool, i'll add it to the agenda15:12
fungihttps://launchpad.net/bugs/1988310 is now public16:10
fungihttps://launchpad.net/bugs/1980349 is now public17:20
fungihttps://launchpad.net/bugs/1977516 is now public17:26

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!