| fungi | gouthamr: similar to the earlier swift hibiscus release discussion, ironic now has their first hibiscus release (38.0.0) so could appear in affected versions lists for ironic advisories going forward | 14:34 |
|---|---|---|
| gouthamr | ++ | 14:40 |
| JayF | fungi: gouthamr: No, 36.0.0 was https://releases.openstack.org/hibiscus/index.html#hibiscus-ironic | 16:09 |
| JayF | fungi: gouthamr: and those have been included in ironic advisories: ) | 16:09 |
| fungi | oh, even better, so >=36.0.0 <38.0.1 now | 16:25 |
| JayF | aye | 16:32 |
| JayF | these are the bugfix branch releases, btw | 16:32 |
| JayF | bugfix/36.0 == 36.0.0 (we *can* release from those branches but rarely do) | 16:32 |
| JayF | I suspect we might do it if we had a mind-blowingly bad Class A | 16:32 |
| JayF | the primary downstream for those is metal3.io, fwiw | 16:33 |
| fungi | gnome is dropping their maximum embargo duration from 90 days to 30: https://blogs.gnome.org/mcatanzaro/2026/07/20/some-changes-to-gnome-security-tracking/ | 21:54 |
| fungi | the rationale used there resonates with my experience in openstack too | 21:54 |
| gouthamr | your memory may be sharper than mine.. how many times have we gone past the embargo timeline this year? i remember two instances (tacker, neutron) in both, i was confused about if the maintainers really cared about the bug (they didn't tell us definitively) .. so it sucked to wait around until the time expired | 22:00 |
| fungi | not often, we've also made exceptions in recent years when bugs took longer due to complexity but were actively being addressed | 22:01 |
| gouthamr | yes, and the motivation michael has for that post (and we see in rare cases here too) doesn't apply in that case? maintainers not paying attention | 22:02 |
| gouthamr | rare now because of our renewed push - not diminishing that :) | 22:02 |
| fungi | but in most cases when it took longer than 30 days it's because work didn't start on it immediately, not uncommon for us to subscribe maintainers and then have a bug sit for a month or two until the looming deadline of the embargo expiration kicks someone into action | 22:03 |
| JayF | If a bug has no meaningful progress in 30d = yes we should bust the embargo | 22:03 |
| JayF | A bug is being actively worked and it just takes a while ... ehh | 22:03 |
| JayF | and it's hard to write a policy with that level of nuance | 22:03 |
| gouthamr | +1 on that - i think you folks discussed that prior to me being around here :) | 22:03 |
| gouthamr | eso: https://review.opendev.org/c/openstack/ossa/+/965369 | 22:04 |
| gouthamr | we could bounce that to openstack-discuss and/or the TC and see if fireworks fly :) | 22:05 |
| fungi | probably, but that's something for tomorrow's fungi (or next week's fungi) to think about. tonight's fungi is going to go relax for a while | 22:06 |
| gouthamr | easy-chair, sea breeze and a wicked weed libation | 22:07 |
| opendevreview | Carlos Eduardo proposed openstack/security-doc master: OSSN-0104: Resource locks unauthorized filtering https://review.opendev.org/c/openstack/security-doc/+/999341 | 22:11 |
Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!