| JayF | https://bugs.launchpad.net/ironic/+bug/2148317 is now public | 17:46 |
|---|---|---|
| sean-k-mooney | ouch | 18:19 |
| sean-k-mooney | i assume like most other tokens generated by a service form config that woudl have been an admin token used to talke to swift | 18:20 |
| sean-k-mooney | unless ye have swap to using only service tokens for that | 18:20 |
| JayF | https://bugs.launchpad.net/ossa/+bug/2148310 is now public | 18:35 |
| JayF | I'd prefer not talk about the specifics in IRC, to be honest. Unembargoed doesn't mean I wanna lay a map out for folks. We have patches already in flight to fix this in master. | 18:36 |
| JayF | (re:2148317) | 18:36 |
| sean-k-mooney | fair | 20:24 |
| opendevreview | Jay Faulkner proposed openstack/ossa master: OSSA-2026-008: Errata 1 - add CVE https://review.opendev.org/c/openstack/ossa/+/986724 | 22:56 |
| JayF | fungi: rosmaita: gouthamr: ^ Do we re-email on errata when it's just adding a CVE number? | 22:56 |
| JayF | (no rush I'm boarding a plane shortly and won't be able to followup today anyway) | 22:57 |
| gouthamr | LGTM JayF | 23:07 |
| gouthamr | ni, we don't need to re-email imo | 23:07 |
| JayF | I agree but making sure that matches with previous cases | 23:07 |
| JayF | and if that's not the policy ... we should change the policy given how long it can take to get CVEs | 23:08 |
| gouthamr | fungi sent this a while ago when we had an incorrect CVE: https://lists.openstack.org/archives/list/openstack-discuss@lists.openstack.org/message/VREZ2RAENJDE4VCHMDR3PT7H6EH77JY7/ | 23:09 |
| JayF | incorrect is a bit different than null->[not null] :D | 23:10 |
| gouthamr | oh wait, we've done one for CVE assignment: https://lists.openstack.org/archives/list/openstack-discuss@lists.openstack.org/message/AX3KINWQCESVJLSZPLLFEKXRXHWJDOKK/ | 23:10 |
| JayF | do you mind shipping that one out for me? | 23:10 |
| gouthamr | yes can do | 23:10 |
| JayF | thank you | 23:10 |
| gouthamr | (will merge this in a little bit if noone else looks) | 23:13 |
| fungi | JayF: it's a judgement call, maybe worth skipping if the noise level is high or unrelated work is overwhelming, but yes i have done it in the past when time allows | 23:18 |
| fungi | mostly to deter random companies from assigning their own | 23:19 |
Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!