15:00:17 #startmeeting security 15:00:18 Meeting started Thu Jun 11 15:00:17 2020 UTC and is due to finish in 60 minutes. The chair is gagehugo. Information about MeetBot at http://wiki.debian.org/MeetBot. 15:00:20 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 15:00:22 The meeting name has been set to 'security' 15:00:34 #link https://etherpad.opendev.org/p/security-agenda agenda 15:01:50 o/ 15:02:30 ohai 15:02:37 also listening to the board meeting 15:03:57 fungi: o/ 15:04:13 #topic refresh security-doc-core 15:04:34 ahh, yeah, so this came up last week with the cinder ossn 15:04:50 we've discussed this before as well iirc 15:04:55 basically we have folks submit ossn additions to the security guide 15:05:05 however it no longer has any active reviewers 15:05:39 folks interested in reviewing and approving these additions, at least ossn, should be added to the group in gerrit 15:06:00 in the meantime we fall back on pestering the doc-core reviewers to approve changes 15:06:01 sure 15:07:51 last time when we reached out to those listed, a lot of the emails were invalid 15:09:05 right, we probably ought to remove them 15:10:11 i suggest we ask the docs team to empty out that group and add new folks who initially volunteer to be reviewers for it 15:10:31 i'm happy to put my name in there, at least to help get ossn changes merged 15:10:44 ok, I can reach out and ask 15:11:54 Is there a link to the cinder ossn discussion from last week I can reference? 15:14:05 otherwise I'll just mention it 15:14:28 #topic meeting times 15:14:43 So we discussed last week about changing both the meeting time and frequency for the security sig 15:15:22 I'd be up for making a poll on the mailing list to gauge interest in timeslots 15:16:56 oh, discussion with the docs team? yeah, let me get you a link 15:17:53 cool 15:19:08 #link http://eavesdrop.openstack.org/irclogs/%23openstack-doc/%23openstack-doc.2020-06-03.log.html#t2020-06-03T17:25:07 security-doc-core discussion with tech writing sig 15:20:13 nice 15:20:56 #topic security sig newsletter 15:21:16 I will start getting these out when I can, might change it up a bit, not sure yet 15:21:55 some months nothing happens, others is a whole lot more exciting 15:22:03 meh, it's not critical 15:22:18 yeah, it's a nice to have 15:22:28 the sig governance requirements aren't specific on how frequently we need to report (or even how) 15:22:53 I basically copied it from keystone anyway when we used to do weekly reports 15:22:59 i agree the newsletters are nice, but if they aren't at a regular frequency i don't see that as a problem 15:23:23 I think after someone from the PTG in Denver asked if we could do something like that 15:24:03 anyway 15:24:11 #topic clean up security wiki/docs 15:24:40 As per discussions from last week, the wiki/docs for the security sig have a lot of outdated info on them, mostly software projects that are no longer under the sig 15:24:56 we can clean those up when time allows 15:25:07 #topic open discussion 15:25:12 fungi: anything else for this week? 15:25:34 there was an ossn published last week 15:26:35 #link Clean up Security SIG Wiki and Guide pages 15:26:38 whoops 15:26:40 #link https://wiki.openstack.org/wiki/OSSN/OSSN-0086 Dell EMC ScaleIO/VxFlex OS Backend Credentials Exposure 15:26:45 thanks 15:28:34 also i opened up a couple more expired embargoes 15:29:09 #link https://launchpad.net/bugs/1866614 CSV Injection in instance edit form in the name field 15:29:09 Launchpad bug 1866614 in OpenStack Security Advisory "CSV Injection in instance edit form in the name field" [Undecided,Incomplete] 15:29:36 #link https://launchpad.net/bugs/1866725 DVR denial of service observed when using DVR+VLAN project networks 15:29:36 Launchpad bug 1866725 in OpenStack Security Advisory "DVR denial of service observed when using DVR+VLAN project networks" [Undecided,Incomplete] 15:30:26 and the manila team also opened up an old private report since fixed in ussuri 15:30:46 no, sorry, mistral 15:31:26 #link https://launchpad.net/bugs/1785657 Denial of service through YAML anchors expansion (Billion Laughs) 15:31:26 Launchpad bug 1785657 in Mistral "Denial of service through YAML anchors expansion (Billion Laughs)" [High,Fix released] - Assigned to Eyal B (eyalb1) 15:31:59 i think that's the only other news i'm aware of besides the ptg discussions we had 15:32:18 i still have a to do item to propose barbican as an openstack "base service" 15:33:09 * redrobot sneaks in through the back 15:35:05 ok 15:35:13 thanks fungi: have a good rest of the week 15:35:16 #endmeeting