Monday, 2025-04-14

gouthamrthis list doesn't seem accurate, does it? https://launchpad.net/~ossg-coresec/+members#active 19:43
gouthamrthis one seems closer to reality: https://launchpad.net/~openstack-vuln-mgmt/+members#active19:45
fungithey were two different groups19:47
gouthamryep; maybe ossg-coresec should be reformed, or retired?19:48
fungithe ossg (openstack security group) was a collection of volunteer security folks from various companies with interests in improving openstack's overall security. the ossg later became the security project, and was eventually retired when it became defunct19:48
fungithe ossg is loosely succeeded by the openstack security sig now19:48
gouthamrah, that LP group is still linked out of https://wiki.openstack.org/wiki/Security_Teams and https://docs.openstack.org/project-team-guide/vulnerability-management.html 19:49
fungii agree "something" needs to be done with it, but am not in a position to look closely at the state of it at the moment19:49
gouthamri can fix the link to begin with19:49
fungithanks19:49
fungithe vmt was/is separate from the ossg, originally the ossg served as the maintainers of the openstack security guide and the openstack security notes publications (not to be confused with security advisoris, which the vmt handles)19:50
gouthamrdoes the VMT now handle those bits? or OSSNs are still under the security-sig's purview?19:52
gouthamrsorry, i should just read further :D 19:56
gouthamrhttps://wiki.openstack.org/wiki/Security-SIG 19:56
fungiit's fuzzy, there's no clear responsible party, it's more about who feels like taking care of it19:56
* gouthamr is just used to the "ask fungi" route19:57
gouthamrhttps://review.opendev.org/c/openstack/project-team-guide/+/947150/20:07
gouthamrhttps://wiki.openstack.org/wiki/Security_Teams20:07
gouthamri fixed these two ^ 20:07
fungithanks!!!20:07
fungialso i think we should look at moving anything of importance out of the Security-SIG wiki into a governance-sigs file like i did with https://governance.openstack.org/sigs/tact-sig.html20:09
gouthamrvery little i'd think20:51
gouthamrhttps://security.openstack.org/ has most of the relevant info20:52
fungiyeah, even better idea!20:52
gouthamrperhaps only the bits around "how can i help" are missing from it20:52
fungisecurity.o.o should be able to double as a security sig page, with a little minor improvement20:53
fungidunno why it didn't occur to me20:54
opendevreviewOpenStack Proposal Bot proposed openstack/security-doc master: Updated from openstack-manuals  https://review.opendev.org/c/openstack/security-doc/+/94716623:56

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!