Friday, 2024-03-15

opendevreviewOpenStack Release Bot proposed openstack/designate-dashboard stable/2024.1: Update .gitreview for stable/2024.1  https://review.opendev.org/c/openstack/designate-dashboard/+/91330609:54
opendevreviewOpenStack Release Bot proposed openstack/designate-dashboard stable/2024.1: Update TOX_CONSTRAINTS_FILE for stable/2024.1  https://review.opendev.org/c/openstack/designate-dashboard/+/91330709:54
opendevreviewOpenStack Release Bot proposed openstack/designate-dashboard master: Update master for stable/2024.1  https://review.opendev.org/c/openstack/designate-dashboard/+/91330809:54
opendevreviewOpenStack Release Bot proposed openstack/designate stable/2024.1: Update .gitreview for stable/2024.1  https://review.opendev.org/c/openstack/designate/+/91330909:55
opendevreviewOpenStack Release Bot proposed openstack/designate stable/2024.1: Update TOX_CONSTRAINTS_FILE for stable/2024.1  https://review.opendev.org/c/openstack/designate/+/91331009:55
opendevreviewOpenStack Release Bot proposed openstack/designate master: Update master for stable/2024.1  https://review.opendev.org/c/openstack/designate/+/91331109:56
opendevreviewMerged openstack/designate stable/2024.1: Update .gitreview for stable/2024.1  https://review.opendev.org/c/openstack/designate/+/91330911:16
opendevreviewMerged openstack/designate-dashboard master: Update master for stable/2024.1  https://review.opendev.org/c/openstack/designate-dashboard/+/91330811:17
opendevreviewMerged openstack/designate-dashboard stable/2024.1: Update .gitreview for stable/2024.1  https://review.opendev.org/c/openstack/designate-dashboard/+/91330611:17
opendevreviewMerged openstack/designate-dashboard stable/2024.1: Update TOX_CONSTRAINTS_FILE for stable/2024.1  https://review.opendev.org/c/openstack/designate-dashboard/+/91330711:17
opendevreviewMerged openstack/designate stable/2024.1: Update TOX_CONSTRAINTS_FILE for stable/2024.1  https://review.opendev.org/c/openstack/designate/+/91331011:21
opendevreviewMerged openstack/designate master: Update master for stable/2024.1  https://review.opendev.org/c/openstack/designate/+/91331111:21
fungijohnsom: any idea if anyone from rh ever opened an upstream bug report about https://access.redhat.com/security/cve/CVE-2023-6725 ? i got e-mail from rh product security to let me know that they determined the same bug exists in the upstream designate project13:40
fricklerfungi: johnsom: to me that looks like an issue in the deployment tooling, not in designate. I don't think anyone expects our devstack deployment to be secured like that?13:57
fungiyeah, i really don't know what the person in rh product security meant by "I heard back from the engineers that it is in fact present in the upstream repository."13:58
fricklerthe /etc/designate/private directory doesn't exist in designate afaict. neither in kolla fwiw14:00
johnsomfungi: it is a tripleo issue, not designate14:04
fungiyes, that's what i thought and so when they first reached out to me to ask i said if it's just affecting tripleo then they didn't need to coordinate with us, but that if a suspected vulnerability also affects an upstream project then to please let us know14:05
fungimaybe they don't understand the difference?14:05
fungii'm e-mailing back again to triple-check (pun intended)14:05

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!