Friday, 2026-08-07

opendevreviewGoutham Pacha Ravi proposed openstack/security-doc master: OSSN-0105: Glance legacy Tasks import SSRF  https://review.opendev.org/c/openstack/security-doc/+/99621005:25
opendevreviewMerged openstack/security-doc master: OSSN-0105: Glance legacy Tasks import SSRF  https://review.opendev.org/c/openstack/security-doc/+/99621014:00
opendevreviewJulia Kreger proposed openstack/security-doc master: [OSSN-0106] Ironic API ramdisk endpoints require network-level access controls  https://review.opendev.org/c/openstack/security-doc/+/100012016:03
-opendevstatus- NOTICE: The Gerrit service on review.opendev.openstack.org will be offline momentarily at 18:00 UTC for a patch upgrade (just under an hour from now), but should return within a few minutes.17:12
gouthamrdo you mind me not sending email for OSSN-0104 until Monday? 17:29
fungii don't see any problem with that17:29
gouthamrack :) want to try and use the same criteria for emailing OSSNs as our OSSA publishing.. although, mondays seem okay - let me know if you have a preference for consistency :) 17:30
gouthamrOSSN-0105*17:31
JayFI would not have merged it on a Friday; TBH17:31
JayFnow that it's merged I feel you have responsibility to announce, regardless of the day17:32
gouthamri prepped it late on thursday :D ran the risk 17:32
JayFI don't feel this strongly; but I do think any delay once it's merged is just completely cosmetic17:32
JayFyou already ruined the weekend by making it official :P 17:32
gouthamryeah, cosmetic.. but, it'll get buried in inboxes etc, or someone will hate me for making them think of things on a friday if they do happen to notice17:33
JayFburied in inboxes is not a case I considered17:33
JayFbut yeah I generally take that policy to mean "don't merge OSSA/OSSN except on Tues-Thurs"17:33
JayFbecause at least in my mental modeling, merge+email notification are kinda atomic because they are the same thing in different venues17:33
gouthamrack; can align with that thought.. 17:34
fungiwe've avoided it for embargoed/coordinated disclosure, but for already-public fixes we've historically just announced those as soon as they're ready17:38
fungiand it's not been uncommon for them to take several days to complete at a lower priority17:39
gouthamryes, in this case, it was WIPed for a while gathering patches17:39
JayFI've stuck to it even for public stuff, but TBH that's just a nice rule for preserving Mondays/Fridays for more forward-looking stuff17:41
-opendevstatus- NOTICE: The Gerrit service on review.opendev.org is going offline momentarily for a patch upgrade, but should return within a few minutes.18:03
opendevreviewSofia Sarhiri proposed openstack/security-doc master: Convert 88 OSSN plain text files to YAML format in preparation for automated build pipeline. Plain text originals retained alongside YAML files temporarily. New OSSNs should be written in YAML going forward, same as OSSAs.  https://review.opendev.org/c/openstack/security-doc/+/99513720:10
opendevreviewSofia Sarhiri proposed openstack/security-doc master: Update README and add YAML template for security notes  https://review.opendev.org/c/openstack/security-doc/+/99513820:10
opendevreviewSofia Sarhiri proposed openstack/security-doc master: Reformat OSSN YAML files to OSSA-style format  https://review.opendev.org/c/openstack/security-doc/+/99515720:10
opendevreviewSofia Sarhiri proposed openstack/security-doc master: added two lines to tools/build-all-rst.sh for the sphinx build process. Added security-notes/conf.py and used security-guide/conf.py as the template  https://review.opendev.org/c/openstack/security-doc/+/99885820:10
opendevreviewSofia Sarhiri proposed openstack/security-doc master: added ossn_vmt.py because the source files are yaml and it parses for sphinx  https://review.opendev.org/c/openstack/security-doc/+/99885920:10
opendevreviewSofia Sarhiri proposed openstack/security-doc master: added ossn.jinja to format the web pages and yaml files, as well as index.rst. running build  https://review.opendev.org/c/openstack/security-doc/+/99886020:10
opendevreviewSofia Sarhiri proposed openstack/security-doc master: Add OSSN build pipeline for security-notes  https://review.opendev.org/c/openstack/security-doc/+/99886120:10
opendevreviewSofia Sarhiri proposed openstack/security-doc master: Improve OSSN YAML file formatting and content UI  https://review.opendev.org/c/openstack/security-doc/+/100014720:10
opendevreviewSofia Sarhiri proposed openstack/security-doc master: Convert 88 OSSN plain text files to YAML format in preparation for automated build pipeline. Plain text originals retained alongside YAML files temporarily. New OSSNs should be written in YAML going forward, same as OSSAs.  https://review.opendev.org/c/openstack/security-doc/+/99515720:19
opendevreviewSofia Sarhiri proposed openstack/security-doc master: added two lines to tools/build-all-rst.sh for the sphinx build process. Added security-notes/conf.py and used security-guide/conf.py as the template  https://review.opendev.org/c/openstack/security-doc/+/99886120:19
opendevreviewSofia Sarhiri proposed openstack/security-doc master: Improve OSSN YAML file formatting and content UI  https://review.opendev.org/c/openstack/security-doc/+/100014720:19
opendevreviewSofia Sarhiri proposed openstack/security-doc master: Convert OSSN plain text files to YAML format  https://review.opendev.org/c/openstack/security-doc/+/100015420:47
opendevreviewSofia Sarhiri proposed openstack/security-doc master: Add OSSN build pipeline for security-notes  https://review.opendev.org/c/openstack/security-doc/+/100015520:47
opendevreviewSofia Sarhiri proposed openstack/security-doc master: Improve OSSN YAML file formatting and content  https://review.opendev.org/c/openstack/security-doc/+/100015620:47
opendevreviewJay Faulkner proposed openstack/security-doc master: Migrate OSSN txt files to build pipeline  https://review.opendev.org/c/openstack/security-doc/+/100015521:15
JayFsarhiri: ^ 21:18
JayFfungi: gouthamr: sarhiri is going to cleanup some of the formatting, especially in the most recent ones. 1000155 is in a reviewable state though. I am happy to integrate newer OSSNs "just in time" when we're ready to merge this.21:20
gouthamrw00t ty JayF 21:21
gouthamrif i flag minor issues, please don't feel like you should update the change21:21
gouthamrwe can make follow up changes.. 21:21
fungiyeah, it doesn't need to be perfect right at the start21:21
JayFshe has like 3-4 bullets of review feedback from me already that she's expecting to be done by EOD, we hope21:23
gouthamrawesome21:24
JayFso I'm aiming for a merge next week, I'll likely need a just-in-time followup for late-landing OSSNs, but honestly I think we could merge what we have right now and it'd pass muster21:24
gouthamrthank you both for doing this on this fun friday21:24
gouthamr\o/21:24
JayFall I did was ask sarhiri to do it, give some feedback, and beat up in git when it started being a bully :D 21:24
JayFs/in //21:24
opendevreviewSofia Sarhiri proposed openstack/security-doc master: Migrate OSSN txt files to build pipeline  https://review.opendev.org/c/openstack/security-doc/+/100015522:44

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!