15:00:10 #startmeeting security 15:00:11 Meeting started Thu Sep 17 15:00:10 2020 UTC and is due to finish in 60 minutes. The chair is gagehugo. Information about MeetBot at http://wiki.debian.org/MeetBot. 15:00:13 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 15:00:15 The meeting name has been set to 'security' 15:01:56 #link https://etherpad.opendev.org/p/security-agenda agenda 15:02:29 o/ 15:02:54 ohai 15:06:00 #topic open discussion 15:06:05 fungi: o/ 15:06:09 Do you have anything for this week? 15:06:58 trying to remember 15:07:31 nothing recently happened in #openstack-security or on the mailing lists 15:07:49 i don't recall switching any new private bugs public yet 15:08:41 i'm behind on related items on my to do list (moving the security sig wiki article into git, proposing barbican as a base service addition) 15:08:54 \o 15:09:44 oh, possibly worth discussion... 15:09:57 the new distributed leadership model the tc approved this week 15:10:20 soon some project teams may have no ptl at all. they're required to identify a "security liaison" in such cases 15:11:21 #link https://governance.openstack.org/tc/resolutions/20200803-distributed-project-leadership.html 15:11:22 * redrobot is out of the loop on the distributed leadership 15:11:45 i also mentioned it in the announcement about ptl/tc nominations coming up 15:17:50 but yeah nothing else new, at least nothing i can mention in public yet 15:18:48 there have been some interesting qemu breakout and unprivileged crash vulnerabilities announced in the past week or so. that may interest some folks i guess 15:21:49 i would link something comprehensive, but the qemu project doesn't do a very good job of making a discoverable list of their advisories 15:23:56 #link https://security-tracker.debian.org/tracker/source-package/qemu 15:23:59 good enough 15:24:25 problem is even querying mitre is useless because they haven't updated the status on the embargoed assignments 15:26:00 hmm 15:26:07 sorry double meetings 15:26:13 me too, no apologies needed 15:26:21 the distributed leadership is interesting 15:26:27 cdf interop sig meeting is scheduled for the same time as this 15:26:37 at least tc office hours got moved 15:30:17 redrobot fungi: thanks, have a good rest of the week! 15:30:19 #endmeeting