| opendevreview | Goutham Pacha Ravi proposed openstack/security-doc master: OSSN-0105: Glance legacy Tasks import SSRF https://review.opendev.org/c/openstack/security-doc/+/996210 | 05:25 |
|---|---|---|
| opendevreview | Merged openstack/security-doc master: OSSN-0105: Glance legacy Tasks import SSRF https://review.opendev.org/c/openstack/security-doc/+/996210 | 14:00 |
| opendevreview | Julia Kreger proposed openstack/security-doc master: [OSSN-0106] Ironic API ramdisk endpoints require network-level access controls https://review.opendev.org/c/openstack/security-doc/+/1000120 | 16:03 |
| -opendevstatus- NOTICE: The Gerrit service on review.opendev.openstack.org will be offline momentarily at 18:00 UTC for a patch upgrade (just under an hour from now), but should return within a few minutes. | 17:12 | |
| gouthamr | do you mind me not sending email for OSSN-0104 until Monday? | 17:29 |
| fungi | i don't see any problem with that | 17:29 |
| gouthamr | ack :) want to try and use the same criteria for emailing OSSNs as our OSSA publishing.. although, mondays seem okay - let me know if you have a preference for consistency :) | 17:30 |
| gouthamr | OSSN-0105* | 17:31 |
| JayF | I would not have merged it on a Friday; TBH | 17:31 |
| JayF | now that it's merged I feel you have responsibility to announce, regardless of the day | 17:32 |
| gouthamr | i prepped it late on thursday :D ran the risk | 17:32 |
| JayF | I don't feel this strongly; but I do think any delay once it's merged is just completely cosmetic | 17:32 |
| JayF | you already ruined the weekend by making it official :P | 17:32 |
| gouthamr | yeah, cosmetic.. but, it'll get buried in inboxes etc, or someone will hate me for making them think of things on a friday if they do happen to notice | 17:33 |
| JayF | buried in inboxes is not a case I considered | 17:33 |
| JayF | but yeah I generally take that policy to mean "don't merge OSSA/OSSN except on Tues-Thurs" | 17:33 |
| JayF | because at least in my mental modeling, merge+email notification are kinda atomic because they are the same thing in different venues | 17:33 |
| gouthamr | ack; can align with that thought.. | 17:34 |
| fungi | we've avoided it for embargoed/coordinated disclosure, but for already-public fixes we've historically just announced those as soon as they're ready | 17:38 |
| fungi | and it's not been uncommon for them to take several days to complete at a lower priority | 17:39 |
| gouthamr | yes, in this case, it was WIPed for a while gathering patches | 17:39 |
| JayF | I've stuck to it even for public stuff, but TBH that's just a nice rule for preserving Mondays/Fridays for more forward-looking stuff | 17:41 |
| -opendevstatus- NOTICE: The Gerrit service on review.opendev.org is going offline momentarily for a patch upgrade, but should return within a few minutes. | 18:03 | |
| opendevreview | Sofia Sarhiri proposed openstack/security-doc master: Convert 88 OSSN plain text files to YAML format in preparation for automated build pipeline. Plain text originals retained alongside YAML files temporarily. New OSSNs should be written in YAML going forward, same as OSSAs. https://review.opendev.org/c/openstack/security-doc/+/995137 | 20:10 |
| opendevreview | Sofia Sarhiri proposed openstack/security-doc master: Update README and add YAML template for security notes https://review.opendev.org/c/openstack/security-doc/+/995138 | 20:10 |
| opendevreview | Sofia Sarhiri proposed openstack/security-doc master: Reformat OSSN YAML files to OSSA-style format https://review.opendev.org/c/openstack/security-doc/+/995157 | 20:10 |
| opendevreview | Sofia Sarhiri proposed openstack/security-doc master: added two lines to tools/build-all-rst.sh for the sphinx build process. Added security-notes/conf.py and used security-guide/conf.py as the template https://review.opendev.org/c/openstack/security-doc/+/998858 | 20:10 |
| opendevreview | Sofia Sarhiri proposed openstack/security-doc master: added ossn_vmt.py because the source files are yaml and it parses for sphinx https://review.opendev.org/c/openstack/security-doc/+/998859 | 20:10 |
| opendevreview | Sofia Sarhiri proposed openstack/security-doc master: added ossn.jinja to format the web pages and yaml files, as well as index.rst. running build https://review.opendev.org/c/openstack/security-doc/+/998860 | 20:10 |
| opendevreview | Sofia Sarhiri proposed openstack/security-doc master: Add OSSN build pipeline for security-notes https://review.opendev.org/c/openstack/security-doc/+/998861 | 20:10 |
| opendevreview | Sofia Sarhiri proposed openstack/security-doc master: Improve OSSN YAML file formatting and content UI https://review.opendev.org/c/openstack/security-doc/+/1000147 | 20:10 |
| opendevreview | Sofia Sarhiri proposed openstack/security-doc master: Convert 88 OSSN plain text files to YAML format in preparation for automated build pipeline. Plain text originals retained alongside YAML files temporarily. New OSSNs should be written in YAML going forward, same as OSSAs. https://review.opendev.org/c/openstack/security-doc/+/995157 | 20:19 |
| opendevreview | Sofia Sarhiri proposed openstack/security-doc master: added two lines to tools/build-all-rst.sh for the sphinx build process. Added security-notes/conf.py and used security-guide/conf.py as the template https://review.opendev.org/c/openstack/security-doc/+/998861 | 20:19 |
| opendevreview | Sofia Sarhiri proposed openstack/security-doc master: Improve OSSN YAML file formatting and content UI https://review.opendev.org/c/openstack/security-doc/+/1000147 | 20:19 |
| opendevreview | Sofia Sarhiri proposed openstack/security-doc master: Convert OSSN plain text files to YAML format https://review.opendev.org/c/openstack/security-doc/+/1000154 | 20:47 |
| opendevreview | Sofia Sarhiri proposed openstack/security-doc master: Add OSSN build pipeline for security-notes https://review.opendev.org/c/openstack/security-doc/+/1000155 | 20:47 |
| opendevreview | Sofia Sarhiri proposed openstack/security-doc master: Improve OSSN YAML file formatting and content https://review.opendev.org/c/openstack/security-doc/+/1000156 | 20:47 |
| opendevreview | Jay Faulkner proposed openstack/security-doc master: Migrate OSSN txt files to build pipeline https://review.opendev.org/c/openstack/security-doc/+/1000155 | 21:15 |
| JayF | sarhiri: ^ | 21:18 |
| JayF | fungi: gouthamr: sarhiri is going to cleanup some of the formatting, especially in the most recent ones. 1000155 is in a reviewable state though. I am happy to integrate newer OSSNs "just in time" when we're ready to merge this. | 21:20 |
| gouthamr | w00t ty JayF | 21:21 |
| gouthamr | if i flag minor issues, please don't feel like you should update the change | 21:21 |
| gouthamr | we can make follow up changes.. | 21:21 |
| fungi | yeah, it doesn't need to be perfect right at the start | 21:21 |
| JayF | she has like 3-4 bullets of review feedback from me already that she's expecting to be done by EOD, we hope | 21:23 |
| gouthamr | awesome | 21:24 |
| JayF | so I'm aiming for a merge next week, I'll likely need a just-in-time followup for late-landing OSSNs, but honestly I think we could merge what we have right now and it'd pass muster | 21:24 |
| gouthamr | thank you both for doing this on this fun friday | 21:24 |
| gouthamr | \o/ | 21:24 |
| JayF | all I did was ask sarhiri to do it, give some feedback, and beat up in git when it started being a bully :D | 21:24 |
| JayF | s/in // | 21:24 |
| opendevreview | Sofia Sarhiri proposed openstack/security-doc master: Migrate OSSN txt files to build pipeline https://review.opendev.org/c/openstack/security-doc/+/1000155 | 22:44 |
Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!