08:02:30 <yasufum> #startmeeting tacker
08:02:30 <opendevmeet> Meeting started Mon Jul 27 08:02:30 2026 UTC and is due to finish in 60 minutes.  The chair is yasufum. Information about MeetBot at http://wiki.debian.org/MeetBot.
08:02:30 <opendevmeet> Useful Commands: #action #agreed #help #info #idea #link #topic #startvote.
08:02:30 <opendevmeet> The meeting name has been set to 'tacker'
08:02:35 <yasufum> Hi
08:02:53 <yasufum> #link https://etherpad.opendev.org/p/tacker-meeting
08:03:02 <yasufum> So, let's start today's meeting.
08:04:05 <yasufum> The first topic is request for review.
08:05:27 <yasufum> I've uploaded some other patches in addition to on the list on etherpad.
08:05:43 <yasufum> Thank you guys for reviewing for these patches.
08:06:37 <yasufum> Unfortunately, something failure happened on zuul test recently
08:06:47 <yasufum> and we cannot merge any patch.
08:07:25 <yasufum> I'm going to fix it, asking again to review then.
08:07:28 <yasufum> Thanks.
08:07:31 <yasufum> Any comment?
08:08:09 <takahashi-tsc> thanks
08:08:24 <yasufum> ok, thanks.
08:08:47 <yasufum> Let's move on to the second topic.
08:09:01 <yasufum> #topic Formation of a Tacker Core Security Group (VMT) for Security Issue Handling
08:09:30 <yasufum> Thank you for taking the responsibility.
08:10:32 <yasufum> shivam: Could share your proposal and discussion points briefly?
08:10:52 <shivam> yes
08:11:28 <shivam> This discussion topic is related to Formation of a Tacker Core Security Group (VMT) for handling security related issues in Tacker.
08:12:25 <shivam> The proposal suggests creating a dedicated Tacker Vulnerability Management Team (VMT) to handle security issues in a more organized, efficient and confidential way.
08:13:29 <shivam> It is proposed because a recent security report showed that Tacker currently lacks a formal team to coordinate vulnerability handling efficiently.
08:14:22 <shivam> The VMT would act as the main point of contact for receiving, investigating, and managing all security-related reports.
08:15:28 <shivam> The team would include Primary Members to lead and coordinate security issues, and Secondary Members to assist with investigation, testing, and developing fixes.
08:16:44 <shivam> Both primary and secondary members would work together to validate vulnerabilities, assess their impact, prepare fixes, and coordinate responsible disclosure following the OpenStack security process.
08:17:47 <shivam> Primary Members can also assign specific security issues to VMT secondary members based on their expertise and availability for efficient resolution.
08:18:31 <shivam> The proposal also recommends reviewing the team's membership periodically to ensure it remains active and responsive.
08:19:09 <shivam> Finally, I would like to know opinion of the Tacker community on the proposed approach for establishing a Tacker Vulnerability Management Team (VMT)/Core Security Group.
08:19:43 <shivam> Additionally, I request community members to confirm if they are interested in joining the Tacker VMT/CoreSec group.
08:19:59 <shivam> Thank you.
08:21:12 <yasufum> thanks
08:21:22 <yasufum> Any comment?
08:23:04 <yasufum> Unfortunately, I might not able to make contributes so much, but still want to help sometimes as a secondary member.
08:26:31 <shivam> ok, thank you for your confirmation to join the group as a secondary member.
08:27:43 <shivam> I would request other members as well if they can confirm their interest in joining the VMT.
08:28:00 <yasufum> OK
08:28:36 <yasufum> Let's continue to discuss then, thanks.
08:28:50 <takahashi-tsc> At least, I will be primary member, and if somoone can help us, it is very helpful.
08:29:35 <yasufum> OK, thanks.
08:30:08 <yasufum> So, there is no update on the third topic.
08:30:34 <yasufum> Let's close this meeting if no other discussion.
08:30:57 <yasufum> Thank you for joining.
08:30:59 <yasufum> Bye!
08:31:48 <shivam> Thank you, bye.
08:31:51 <yasufum> #endmeeting