Thursday, 2023-09-07

tonybtobias-urdin, fungi: Circling back to: https://meetings.opendev.org/irclogs/%23openstack-security/%23openstack-security.2023-07-27.log.html  Indeed those CVEs are considered duplicates and https://review.opendev.org/q/Ieef7011f48cd2188d4254ff16d90a6465bbabfe3 contains the fixes.11:21
tonybRH does ship fixes against train but they weren't appropriate for upstream.11:22
tobias-urdintonyb: ack, thanks!11:48
fungiyes, thanks for looking into it tonyb!!!11:52
dmendiza[m]No SIG meeting today, I assume?15:15
fungioh, there can be!15:16
fungihave anything to talk about?15:16
dmendiza[m]Not really.  Just making sure y'all know I'm still around 😅15:17
* dmendiza[m] is attempting to be more present in the SIG15:17
fungii still haven't gotten around to trying to restart the discussion about picking a better meeting time, since the previous response was at best lackluster15:17
fungiprobably the most exciting current activity for the vmt is https://launchpad.net/bugs/203097615:18
fungii'll put in the cve request for that today (finally)15:18
fungiat least it's pretty low-impact15:18
dmendiza[m]Yeah, I briefly saw that come through my email.15:18
dmendiza[m]Interesting for sure.15:18
fungibut if you have any feedback on it, feel free to weigh in15:18
fungiit was a borderline case. i'm treating it as if credentials were being leaked in non-debug service logs, but notifications aren't exactly logs. it's just unclear to what extent we provide guidance about how sensitive the contents of those notifications might be and how safe it is to give people access to them15:20
mharleyo/16:16
mharleyJust recording presence. ;-) 16:16
fungiohai!16:24

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!