Tuesday, 2026-02-17

*** bauzas8 is now known as bauzas00:49
opendevreviewJeremy Stanley proposed openstack/ossa master: OSSA-2026-002 / CVE-2026-24708  https://review.opendev.org/c/openstack/ossa/+/97710514:42
fungirosmaita: tonyb: ^ expedited review/approve requested if either of you is around14:42
rosmaitafungi: ack, in a meeting now, will look at the top of the hour14:43
fungino worries, i can self-approve once check succeeds, advisory is due out at the top of the hour14:44
opendevreviewMerged openstack/ossa master: OSSA-2026-002 / CVE-2026-24708  https://review.opendev.org/c/openstack/ossa/+/97710515:01
fungii'm trying to notify mitre about the publication so they can switch the cve detail on, but their webform isn't submitting for me at the moment15:11
fungitried another browser and it went through15:15
*** croeland1 is now known as croelandt15:25
fungioops, looks like we might have had a mismatch on cve numbers in one part of ossa-2026-002, i'll work on errata for that16:35
opendevreviewJeremy Stanley proposed openstack/ossa master: OSSA-2026-002 Errata 1  https://review.opendev.org/c/openstack/ossa/+/97714216:47
fungirosmaita: ^ looks like it was a typo we missed when reviewing the original draft in the bug attachment16:47
rosmaitaoops16:48
rosmaitafungi: LGTM ... not sure there's anyone else around, want me to merge it?16:54
fungiyes please16:55
rosmaitadone16:55
fungii'll get the revised publication circulated once it's up on security.o.o16:55
opendevreviewMerged openstack/ossa master: OSSA-2026-002 Errata 1  https://review.opendev.org/c/openstack/ossa/+/97714217:11
fungigoing over https://orcwg.org/files/cra/resources/white-paper-on-open-source-software-stewards-and-cra.pdf i think the only major thing in there we're not doing today is documenting how we collaborate with other open source projects, e.g. notifying upstreams of dependencies when someone misreports a bug to us that really should have gone to them18:47
fungiwe have done exactly that a number of times in the past, but never included it in our reporting policy18:47
fungii'll try to write up something brief about that, to include in our reporting.rst18:48
opendevreviewJeremy Stanley proposed openstack/ossa master: Reporting vulnerabilities in other software  https://review.opendev.org/c/openstack/ossa/+/97715219:00
fungithere we go19:00

Generated by irclog2html.py 4.0.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!