08:02:30 <yasufum> #startmeeting tacker 08:02:30 <opendevmeet> Meeting started Mon Jul 27 08:02:30 2026 UTC and is due to finish in 60 minutes. The chair is yasufum. Information about MeetBot at http://wiki.debian.org/MeetBot. 08:02:30 <opendevmeet> Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 08:02:30 <opendevmeet> The meeting name has been set to 'tacker' 08:02:35 <yasufum> Hi 08:02:53 <yasufum> #link https://etherpad.opendev.org/p/tacker-meeting 08:03:02 <yasufum> So, let's start today's meeting. 08:04:05 <yasufum> The first topic is request for review. 08:05:27 <yasufum> I've uploaded some other patches in addition to on the list on etherpad. 08:05:43 <yasufum> Thank you guys for reviewing for these patches. 08:06:37 <yasufum> Unfortunately, something failure happened on zuul test recently 08:06:47 <yasufum> and we cannot merge any patch. 08:07:25 <yasufum> I'm going to fix it, asking again to review then. 08:07:28 <yasufum> Thanks. 08:07:31 <yasufum> Any comment? 08:08:09 <takahashi-tsc> thanks 08:08:24 <yasufum> ok, thanks. 08:08:47 <yasufum> Let's move on to the second topic. 08:09:01 <yasufum> #topic Formation of a Tacker Core Security Group (VMT) for Security Issue Handling 08:09:30 <yasufum> Thank you for taking the responsibility. 08:10:32 <yasufum> shivam: Could share your proposal and discussion points briefly? 08:10:52 <shivam> yes 08:11:28 <shivam> This discussion topic is related to Formation of a Tacker Core Security Group (VMT) for handling security related issues in Tacker. 08:12:25 <shivam> The proposal suggests creating a dedicated Tacker Vulnerability Management Team (VMT) to handle security issues in a more organized, efficient and confidential way. 08:13:29 <shivam> It is proposed because a recent security report showed that Tacker currently lacks a formal team to coordinate vulnerability handling efficiently. 08:14:22 <shivam> The VMT would act as the main point of contact for receiving, investigating, and managing all security-related reports. 08:15:28 <shivam> The team would include Primary Members to lead and coordinate security issues, and Secondary Members to assist with investigation, testing, and developing fixes. 08:16:44 <shivam> Both primary and secondary members would work together to validate vulnerabilities, assess their impact, prepare fixes, and coordinate responsible disclosure following the OpenStack security process. 08:17:47 <shivam> Primary Members can also assign specific security issues to VMT secondary members based on their expertise and availability for efficient resolution. 08:18:31 <shivam> The proposal also recommends reviewing the team's membership periodically to ensure it remains active and responsive. 08:19:09 <shivam> Finally, I would like to know opinion of the Tacker community on the proposed approach for establishing a Tacker Vulnerability Management Team (VMT)/Core Security Group. 08:19:43 <shivam> Additionally, I request community members to confirm if they are interested in joining the Tacker VMT/CoreSec group. 08:19:59 <shivam> Thank you. 08:21:12 <yasufum> thanks 08:21:22 <yasufum> Any comment? 08:23:04 <yasufum> Unfortunately, I might not able to make contributes so much, but still want to help sometimes as a secondary member. 08:26:31 <shivam> ok, thank you for your confirmation to join the group as a secondary member. 08:27:43 <shivam> I would request other members as well if they can confirm their interest in joining the VMT. 08:28:00 <yasufum> OK 08:28:36 <yasufum> Let's continue to discuss then, thanks. 08:28:50 <takahashi-tsc> At least, I will be primary member, and if somoone can help us, it is very helpful. 08:29:35 <yasufum> OK, thanks. 08:30:08 <yasufum> So, there is no update on the third topic. 08:30:34 <yasufum> Let's close this meeting if no other discussion. 08:30:57 <yasufum> Thank you for joining. 08:30:59 <yasufum> Bye! 08:31:48 <shivam> Thank you, bye. 08:31:51 <yasufum> #endmeeting