Monday, 2026-05-11

*** zigo_ is now known as zigo08:57
opendevreviewMerged openstack/ossa master: OSSA-2026-012: RCE in Ironic anaconda deploy  https://review.opendev.org/c/openstack/ossa/+/98776416:04
JayFSo ^ that merged, but I'm not seeing it on the security site. I've confirmed that the promote job completed.16:07
fungiwait until 16:10-16:1116:09
JayFah, got it16:09
fungipromotes go into the afs rw volume, which gets synced to the read-only replicas the site is served from roughly every 5 minutes16:10
JayFI thought it might be somethign like that16:11
fungithis is by far the most active year by ossa count in the past decade, and the year's not even half over. one more and we'll tie with 201617:25
fungiwe had 41 in 2014 though, o17:26
fungii'm hoping we don't end up with that many in one year ever again17:26
JayFI sorta think if we don't bust that number this year we never will. Not that I want to or not want to, just that I've seen no evidence the pace isn't continuing to accelarate.17:27
gouthamrgood we're getting several issues patched, and i like the responsiveness from project teams so far.. over the release/year, security-sig/vmt would probably have dealt with most project teams.. we'll likely encounter some that are unable to respond/keep up.. that's a data point that can help the TC that we need some attention.. 20:19

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!