Thursday, 2026-07-30

fungigouthamr: similar to the earlier swift hibiscus release discussion, ironic now has their first hibiscus release (38.0.0) so could appear in affected versions lists for ironic advisories going forward14:34
gouthamr++14:40
JayFfungi: gouthamr: No, 36.0.0 was https://releases.openstack.org/hibiscus/index.html#hibiscus-ironic16:09
JayFfungi: gouthamr: and those have been included in ironic advisories: )16:09
fungioh, even better, so >=36.0.0 <38.0.1 now16:25
JayFaye16:32
JayFthese are the bugfix branch releases, btw16:32
JayFbugfix/36.0 == 36.0.0 (we *can* release from those branches but rarely do)16:32
JayFI suspect we might do it if we had a mind-blowingly bad Class A16:32
JayFthe primary downstream for those is metal3.io, fwiw16:33
fungignome is dropping their maximum embargo duration from 90 days to 30: https://blogs.gnome.org/mcatanzaro/2026/07/20/some-changes-to-gnome-security-tracking/21:54
fungithe rationale used there resonates with my experience in openstack too21:54
gouthamryour memory may be sharper than mine.. how many times have we gone past the embargo timeline this year? i remember two instances (tacker, neutron) in both, i was confused about if the maintainers really cared about the bug (they didn't tell us definitively) .. so it sucked to wait around until the time expired22:00
funginot often, we've also made exceptions in recent years when bugs took longer due to complexity but were actively being addressed22:01
gouthamryes, and the motivation michael has for that post (and we see in rare cases here too) doesn't apply in that case? maintainers not paying attention22:02
gouthamrrare now because of our renewed push - not diminishing that :) 22:02
fungibut in most cases when it took longer than 30 days it's because work didn't start on it immediately, not uncommon for us to subscribe maintainers and then have a bug sit for a month or two until the looming deadline of the embargo expiration kicks someone into action22:03
JayFIf a bug has no meaningful progress in 30d = yes we should bust the embargo22:03
JayFA bug is being actively worked and it just takes a while ... ehh22:03
JayFand it's hard to write a policy with that level of nuance22:03
gouthamr+1 on that - i think you folks discussed that prior to me being around here :) 22:03
gouthamreso: https://review.opendev.org/c/openstack/ossa/+/96536922:04
gouthamrwe could bounce that to openstack-discuss and/or the TC and see if fireworks fly :) 22:05
fungiprobably, but that's something for tomorrow's fungi (or next week's fungi) to think about. tonight's fungi is going to go relax for a while22:06
gouthamreasy-chair, sea breeze and a wicked weed libation22:07
opendevreviewCarlos Eduardo proposed openstack/security-doc master: OSSN-0104: Resource locks unauthorized filtering  https://review.opendev.org/c/openstack/security-doc/+/99934122:11

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!