Tuesday, 2026-05-05

fungiJayF: gouthamr: in the cve request form additional notes i usually indicate whether the bug is under private embargo or is already public. it's helped in the past, but if you've done that and it's not helping i'm unsurprised, they're dealing with the same deluge we are, after all00:48
gouthamrfungi: ack, i've been doing that too; my problem's been that the form fails silently and i need to keep trying different things to get a confirmation :D 14:38
gouthamrbut cid could confirm how his request was filed14:38
opendevreviewJay Faulkner proposed openstack/ossa master: [OSSA-2026-010]: Ironic conf mold token leak  https://review.opendev.org/c/openstack/ossa/+/98686314:56
JayFgouthamr: rosmaita: https://review.opendev.org/c/openstack/ossa/+/986863 edited for review feedback; I will announce this version in about an hour if there's no negative feedback14:57
rosmaitalooking14:57
rosmaitaJayF: looks like you have an extra blank line at the bottom, but also i'd prefer you explicitly say it will not appear in the Hibiscus release15:01
JayFleave that comment and I'll update, I'm in a meeting15:08
JayFty15:08
rosmaitaack15:12
JayFhttps://bugs.launchpad.net/ironic/+bug/2148307 is now public15:23
opendevreviewcid proposed openstack/ossa master: [OSSA-2026-010]: Ironic conf mold token leak  https://review.opendev.org/c/openstack/ossa/+/98686315:41
rosmaitagouthamr: ^^ is a minor update, if you want to renew your +2 and approve the patch15:49
gouthamrdone rosmaita 15:56
rosmaitathanks!15:56
opendevreviewMerged openstack/ossa master: [OSSA-2026-010]: Ironic conf mold token leak  https://review.opendev.org/c/openstack/ossa/+/98686315:57
JayFI'm sending announcements for OSSA-2026-010 now16:39
gouthamr++16:40
JayFAHA! That's what screwed up my last email!16:40
JayFcopy paste from https://a1110360d0aa5b1915ef-de0170061a4c33caf35d62b404ee94ad.ssl.cf5.rackcdn.com/openstack/d1743bf2e3bb48aa9eba6542304af42f/docs/_sources/ossa/OSSA-2026-010.rst.txt -> email compose window16:40
JayFtext formatting (white, because dark mode) copied over16:40
gouthamraccepted on openstack-announce, ty JayF 16:44
fungihttps://www.djangoproject.com/weblog/2026/may/05/security-releases/ is likely of interest to people operating horizon20:32
gouthamri brain dumped some tribal knowledge about bug tracking on launchpad here: https://review.opendev.org/c/openstack/project-team-guide/+/98743321:30
gouthamrwould appreciate a review 21:30
gouthamri asked questions and fixed manila's trackers for security/VMT conformance.. other people may have the same issues21:31
fungithis paramiko audit may be of interest, especially since its continued use has come up in the context of the nascent pqc pop-up team: https://ostif.org/paramiko-audit-complete/22:33
gouthamrthat's a great find, fungi 22:45
fungii can't take credit, it got mentioned on oss-security22:45
gouthamrthey claim all their HIGH and MEDIUM findings are getting addressed in 4.0.022:45
gouthamrafter*22:48
gouthamr4.0.0 was Aug 202522:48
fungiyeah, 5.0.0 it said, i think?22:52
fungicoming later this month22:52

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!