Wednesday, 2025-09-10

tkajinamis there any public document which describes the projects observed by security sig now ?12:50
tkajinam(though the "sig" might be mostly equivalent to fungi12:50
tkajinamI often forget the terminology around security problem management in OpenStack but I hope what I mean is clear12:51
rosmaitatkajinam: maybe this answers your question: https://governance.openstack.org/tc/resolutions/20250317-extend-scope-VMT-cover-all-projects.html12:54
tkajinamrosmaita, ah yes ! thank you !13:00
fungitkajinam: the security sig doesn't necessarily observe specific projects, we're a sig for all of openstack. the vmt oversees reports of suspected vulnerabilities for basically all projects so long as they meet the requirements listed at https://security.openstack.org/repos-overseen.html13:29
fungithe security sig has a page here though the description is likely outdated: 13:33
fungihttps://wiki.openstack.org/wiki/Security-SIG13:33
tkajinamfungi, ok13:57

Generated by irclog2html.py 4.0.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!