*** browne has quit IRC | 00:18 | |
*** sdake has joined #openstack-security | 00:29 | |
*** tmcpeak has quit IRC | 00:32 | |
*** sdake_ has quit IRC | 00:32 | |
*** kutija|away has quit IRC | 00:33 | |
*** dave-mccowan has joined #openstack-security | 00:33 | |
*** tmcpeak has joined #openstack-security | 00:35 | |
*** dave-mcc_ has quit IRC | 00:36 | |
*** sdake_ has joined #openstack-security | 00:39 | |
*** sdake has quit IRC | 00:42 | |
*** hyakuhei1 has joined #openstack-security | 00:53 | |
*** hyakuhei has quit IRC | 00:53 | |
*** bpokorny has quit IRC | 00:56 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 01:06 | |
*** kutija has joined #openstack-security | 01:16 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 01:20 | |
*** hyakuhei1 has quit IRC | 01:23 | |
*** hyakuhei has joined #openstack-security | 01:24 | |
*** jamielennox|away is now known as jamielennox | 01:32 | |
*** bpokorny has joined #openstack-security | 01:44 | |
*** sdake has joined #openstack-security | 01:58 | |
*** sdake_ has quit IRC | 02:01 | |
*** hyakuhei1 has joined #openstack-security | 02:03 | |
*** hyakuhei has quit IRC | 02:03 | |
*** bpokorny has quit IRC | 02:14 | |
*** hyakuhei1 has quit IRC | 02:24 | |
*** hyakuhei has joined #openstack-security | 02:28 | |
*** hyakuhei has quit IRC | 02:35 | |
*** hyakuhei has joined #openstack-security | 02:36 | |
*** tmcpeak has quit IRC | 02:38 | |
*** nkinder__ has joined #openstack-security | 02:50 | |
*** markvoelker has joined #openstack-security | 02:59 | |
*** markvoelker has quit IRC | 03:04 | |
*** jraim has quit IRC | 03:06 | |
*** serverascode has quit IRC | 03:06 | |
*** hyakuhei1 has joined #openstack-security | 03:10 | |
*** hyakuhei has quit IRC | 03:11 | |
*** tmcpeak has joined #openstack-security | 03:13 | |
*** sdake has quit IRC | 03:31 | |
*** sdake has joined #openstack-security | 03:33 | |
*** browne has joined #openstack-security | 03:33 | |
*** sdake has quit IRC | 03:34 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 03:40 | |
*** dave-mccowan has quit IRC | 04:06 | |
*** hyakuhei1 has quit IRC | 04:31 | |
*** hyakuhei has joined #openstack-security | 04:32 | |
*** aswadr has joined #openstack-security | 04:40 | |
*** hyakuhei has quit IRC | 04:46 | |
*** markvoelker has joined #openstack-security | 04:48 | |
*** hyakuhei has joined #openstack-security | 04:49 | |
*** sdake has joined #openstack-security | 04:51 | |
*** markvoelker has quit IRC | 04:53 | |
*** tmcpeak has quit IRC | 05:15 | |
*** hyakuhei has quit IRC | 05:36 | |
*** hyakuhei has joined #openstack-security | 05:45 | |
*** sdake has quit IRC | 06:16 | |
*** jraim has joined #openstack-security | 06:17 | |
*** alex_klimov has joined #openstack-security | 06:21 | |
*** sweston has quit IRC | 06:34 | |
*** serverascode has joined #openstack-security | 06:37 | |
*** hyakuhei has quit IRC | 07:05 | |
*** hyakuhei1 has joined #openstack-security | 07:05 | |
*** hyakuhei has joined #openstack-security | 07:15 | |
*** hyakuhei1 has quit IRC | 07:15 | |
*** browne has quit IRC | 07:27 | |
*** sdake has joined #openstack-security | 07:29 | |
*** sweston has joined #openstack-security | 07:37 | |
*** markvoelker has joined #openstack-security | 07:37 | |
*** sdake_ has joined #openstack-security | 07:39 | |
*** sdake has quit IRC | 07:43 | |
*** markvoelker has quit IRC | 07:43 | |
*** sdake has joined #openstack-security | 07:44 | |
*** sdake_ has quit IRC | 07:47 | |
*** sdake_ has joined #openstack-security | 08:22 | |
*** sdake has quit IRC | 08:25 | |
*** hyakuhei1 has joined #openstack-security | 08:32 | |
*** hyakuhei has quit IRC | 08:32 | |
*** sdake_ has quit IRC | 08:34 | |
*** sdake has joined #openstack-security | 08:36 | |
*** sdake_ has joined #openstack-security | 08:39 | |
*** sdake_ has quit IRC | 08:41 | |
*** sdake has quit IRC | 08:42 | |
*** hyakuhei has joined #openstack-security | 09:14 | |
*** hyakuhei1 has quit IRC | 09:14 | |
*** markvoelker has joined #openstack-security | 09:27 | |
*** markvoelker has quit IRC | 09:32 | |
*** hyakuhei has quit IRC | 09:38 | |
*** hyakuhei has joined #openstack-security | 09:38 | |
*** hyakuhei has quit IRC | 09:59 | |
*** hyakuhei1 has joined #openstack-security | 09:59 | |
*** hyakuhei has joined #openstack-security | 10:56 | |
*** hyakuhei1 has quit IRC | 10:56 | |
openstackgerrit | Stanislaw Pitucha proposed stackforge/anchor: CA doesn't need to be read-only https://review.openstack.org/189662 | 11:21 |
---|---|---|
*** markvoelker has joined #openstack-security | 11:29 | |
*** markvoelker has quit IRC | 11:34 | |
*** hyakuhei has quit IRC | 11:37 | |
*** hyakuhei has joined #openstack-security | 11:40 | |
*** aswadr has quit IRC | 11:41 | |
*** aswadr has joined #openstack-security | 11:43 | |
*** HoangCX has joined #openstack-security | 11:59 | |
*** HoangCX has quit IRC | 12:00 | |
*** hyakuhei1 has joined #openstack-security | 12:15 | |
*** hyakuhei has quit IRC | 12:15 | |
*** dave-mccowan has joined #openstack-security | 12:34 | |
*** tmcpeak has joined #openstack-security | 12:39 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 12:41 | |
*** hyakuhei1 has quit IRC | 12:41 | |
*** bknudson has quit IRC | 12:41 | |
*** hyakuhei has joined #openstack-security | 12:46 | |
*** hyakuhei1 has joined #openstack-security | 13:05 | |
*** hyakuhei has quit IRC | 13:06 | |
*** sdake has joined #openstack-security | 13:17 | |
*** jamielennox is now known as jamielennox|away | 13:23 | |
*** singlethink has joined #openstack-security | 13:30 | |
*** browne has joined #openstack-security | 13:32 | |
*** WaltBarnes has joined #openstack-security | 13:34 | |
*** bknudson has joined #openstack-security | 13:38 | |
*** singleth_ has joined #openstack-security | 13:54 | |
*** sdake has quit IRC | 13:56 | |
*** localloop127 has joined #openstack-security | 13:57 | |
*** singlethink has quit IRC | 13:58 | |
*** asrangne has joined #openstack-security | 14:13 | |
*** aswadr has quit IRC | 14:16 | |
*** jian5397 has joined #openstack-security | 14:39 | |
*** voodookid has joined #openstack-security | 14:39 | |
*** salv-orl_ has joined #openstack-security | 14:51 | |
*** salv-orlando has quit IRC | 14:52 | |
*** sdake has joined #openstack-security | 15:05 | |
*** sdake has quit IRC | 15:06 | |
*** salv-orl_ has quit IRC | 15:06 | |
*** sdake has joined #openstack-security | 15:07 | |
*** markvoelker has joined #openstack-security | 15:07 | |
*** salv-orlando has joined #openstack-security | 15:08 | |
*** bpokorny has joined #openstack-security | 15:09 | |
*** markvoelker has quit IRC | 15:12 | |
*** dwyde has joined #openstack-security | 15:19 | |
*** hyakuhei1 has quit IRC | 15:23 | |
*** hyakuhei has joined #openstack-security | 15:29 | |
*** sdake has quit IRC | 15:30 | |
*** singleth_ has quit IRC | 15:38 | |
*** dwyde has quit IRC | 15:48 | |
*** dave-mccowan has quit IRC | 15:54 | |
*** dwyde has joined #openstack-security | 15:56 | |
*** singlethink has joined #openstack-security | 16:11 | |
*** alex_klimov has quit IRC | 16:12 | |
*** salv-orlando has quit IRC | 16:33 | |
*** elmiko is now known as _elmiko | 16:41 | |
sigmavirus24 | y'all will get a kick out of this: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-1729 | 16:45 |
sigmavirus24 | via http://www.openwall.com/lists/oss-security/2015/06/09/4 | 16:45 |
*** markvoelker has joined #openstack-security | 16:56 | |
*** markvoelker has quit IRC | 17:01 | |
*** salv-orlando has joined #openstack-security | 17:09 | |
tmcpeak | sigmavirus24: lol! | 17:23 |
*** hyakuhei has quit IRC | 17:28 | |
*** hyakuhei has joined #openstack-security | 17:28 | |
*** asrangne has quit IRC | 17:30 | |
*** _elmiko is now known as elmiko | 17:52 | |
*** hyakuhei has quit IRC | 17:58 | |
*** hyakuhei has joined #openstack-security | 18:01 | |
tmcpeak | browne: awesome!!! | 18:01 |
*** dwyde has quit IRC | 18:03 | |
*** sdake has joined #openstack-security | 18:07 | |
*** dwyde has joined #openstack-security | 18:09 | |
browne | tmcpeak: no problem | 18:11 |
tmcpeak | :) :) | 18:14 |
*** markvoelker has joined #openstack-security | 18:45 | |
*** hyakuhei has quit IRC | 18:46 | |
*** hyakuhei has joined #openstack-security | 18:47 | |
*** openstackgerrit has quit IRC | 18:48 | |
*** openstackgerrit has joined #openstack-security | 18:48 | |
*** markvoelker has quit IRC | 18:49 | |
*** jian5397 has left #openstack-security | 18:54 | |
tmcpeak | sigmavirus24: checking out your plugin work now | 18:59 |
tmcpeak | looks good | 18:59 |
tmcpeak | just making sure I have my head wrapped around it | 18:59 |
sigmavirus24 | I still need to address some of Eric's concerns | 18:59 |
sigmavirus24 | Yeah I tried to comment somethings that I thought people might find odd | 19:00 |
sigmavirus24 | I also need to explain taht I didn't add entry-points for our existing plugins | 19:00 |
sigmavirus24 | And that the info about which plugins were detected doesn't print anything at all if none were detected | 19:00 |
tmcpeak | yea, those are small things though. The comments are helpful | 19:01 |
*** jian5397 has joined #openstack-security | 19:02 | |
*** singlethink has quit IRC | 19:07 | |
*** sdake has quit IRC | 19:31 | |
*** singlethink has joined #openstack-security | 19:31 | |
tmcpeak | sigmavirus24: you around? | 19:37 |
sigmavirus24 | sort of | 19:37 |
sigmavirus24 | what's up? | 19:37 |
tmcpeak | when I'm running your change without specifying a format I'm getting: | 19:38 |
tmcpeak | Traceback (most recent call last): | 19:38 |
tmcpeak | File "/usr/local/bin/bandit", line 10, in <module> | 19:38 |
tmcpeak | sys.exit(main()) | 19:38 |
tmcpeak | File "/usr/local/lib/python2.7/site-packages/bandit/bandit.py", line 148, in main | 19:38 |
tmcpeak | args.output_format) | 19:38 |
tmcpeak | File "/usr/local/lib/python2.7/site-packages/bandit/core/manager.py", line 112, in output_results | 19:38 |
tmcpeak | output_format=output_format | 19:38 |
tmcpeak | File "/usr/local/lib/python2.7/site-packages/bandit/core/result_store.py", line 123, in report | 19:38 |
tmcpeak | self._write_report(files_list, scores, excluded_files) | 19:38 |
tmcpeak | File "/usr/local/lib/python2.7/site-packages/bandit/core/result_store.py", line 88, in _write_report | 19:38 |
tmcpeak | formatter = formatters_mgr['txt'] | 19:38 |
tmcpeak | if I don't specify an output format | 19:38 |
tmcpeak | does that work for you? there might be something shady in my environment (it's happened before) | 19:38 |
sigmavirus24 | let me make sure everything's commited and pushed up | 19:39 |
sigmavirus24 | It was working before though. (me is reinstalling bandit) | 19:40 |
tmcpeak | looks like my extensions aren't loaded at the place I'm trying to use them | 19:41 |
sigmavirus24 | Nope. Works fine for me. I'm testing it by doing `tox -r -e py{..} --notest` then `.tox/py{..}/bin/bandit -r bandit/` | 19:41 |
sigmavirus24 | looks like you have it installed globally though | 19:41 |
tmcpeak | I'm testing like this: bandit -r ~/Documents/projects/OpenStack_projects/keystone (no virtual env) | 19:41 |
sigmavirus24 | I assume you had it installed globally before as well? | 19:42 |
tmcpeak | yep | 19:42 |
tmcpeak | I removed it just to make sure | 19:42 |
sigmavirus24 | Was it editable? | 19:42 |
sigmavirus24 | I've seen that cause problems with PBR+entry-points before | 19:42 |
tmcpeak | editable? | 19:42 |
sigmavirus24 | pip install -e | 19:42 |
sigmavirus24 | You can install something so that when you edit it, it updates automagically | 19:43 |
tmcpeak | well I'm currently doing "python setup.py install" | 19:43 |
sigmavirus24 | Oh | 19:43 |
sigmavirus24 | You can do `pip install .` | 19:43 |
sigmavirus24 | That makes it much easier to uninstall | 19:43 |
sigmavirus24 | Then you can just do `pip uninstall bandit` | 19:43 |
sigmavirus24 | or `pip install --force-reinstall .` | 19:43 |
* sigmavirus24 doesn't know how well setuptools installs over itself with PBR | 19:44 | |
tmcpeak | ahh | 19:45 |
tmcpeak | let me try that | 19:45 |
tmcpeak | lol, ok | 19:45 |
tmcpeak | when I went all the way through the rabbit hole of "pip uninstall bandit" until it said not found, and then "pip install ." now it works :) | 19:45 |
tmcpeak | false alarm | 19:45 |
sigmavirus24 | hah | 19:46 |
sigmavirus24 | Yeah | 19:46 |
sigmavirus24 | pip can't uninstall things that were `python setup.py install`'d | 19:46 |
tmcpeak | so I think the answer to how well setuptools installs over itself is "crappily" | 19:46 |
tmcpeak | ;) | 19:46 |
sigmavirus24 | ;) | 19:46 |
sigmavirus24 | I think typically setuptools would do just fine | 19:46 |
tmcpeak | cool, thanks man.. back on the testing | 19:46 |
sigmavirus24 | I don't know how PBR affects that though | 19:46 |
*** localloop127 has quit IRC | 20:01 | |
*** jamielennox|away is now known as jamielennox | 20:01 | |
tmcpeak | browne: around? | 20:02 |
sigmavirus24 | tmcpeak: get it to work? | 20:05 |
tmcpeak | sigmavirus24: yep! it looks good to me | 20:05 |
tmcpeak | with the exception of fixing Eric's concerns | 20:06 |
tmcpeak | also.. I didn't see the plugin string printed in parser epilog at all | 20:06 |
sigmavirus24 | tmcpeak: including adding a blueprint? | 20:06 |
tmcpeak | oh, yeah.. I should have dropped a comment | 20:06 |
tmcpeak | I don't think we need a blueprint | 20:06 |
sigmavirus24 | tmcpeak: right, with no plugins registered, it doesn't print them | 20:06 |
sigmavirus24 | I don't mind writing a blueprint | 20:06 |
tmcpeak | we've discussed the work here | 20:06 |
tmcpeak | I don't think we need one | 20:06 |
* sigmavirus24 just wants to know what he has to do this weekend | 20:06 | |
tmcpeak | in my mind blueprint would be if somebody has work in mind but wants community buy in first | 20:07 |
tmcpeak | I think we're small enough we can just discuss it here | 20:07 |
tmcpeak | besides, blueprint after the fact is kind of pointless :) | 20:07 |
sigmavirus24 | Yeah that's why I threw up a blueprint for the use of thread/multiprocessing | 20:07 |
sigmavirus24 | We've done that in glance =P | 20:07 |
sigmavirus24 | I should update that copyright too. Rackspace wasn't paying me for this stuff so it's technically just OpenStack Foundation copyright | 20:08 |
tmcpeak | oh yeah, I've got to check that out | 20:08 |
tmcpeak | sigmavirus24: let it not be said that you don't know how to party ;) | 20:08 |
sigmavirus24 | lol | 20:08 |
sigmavirus24 | I just have experience with static analysis tools and what makes them good | 20:09 |
sigmavirus24 | took a long time for flake8 to get where it is | 20:09 |
tmcpeak | I'm glad to have you hacking away on Bandit now :) | 20:10 |
tmcpeak | since you're here, what are your thoughts on Joe's comments here: | 20:10 |
tmcpeak | https://review.openstack.org/#/c/179566/ | 20:10 |
tmcpeak | I can explain the surrounding lines to print - we're printing a whole statement, we don't really have any way to parse the relevant part of the statement out | 20:11 |
tmcpeak | the slow thing puzzles me | 20:11 |
tmcpeak | I've never seen Bandit even take a minute | 20:11 |
tmcpeak | I'm open to the suggestion to suppress listing excluded files | 20:11 |
sigmavirus24 | tmcpeak: Bandit easily took 10 minutes (I stopped keeping track) when I ran it against glance | 20:11 |
sigmavirus24 | Yeah | 20:11 |
tmcpeak | what? really? | 20:11 |
*** hyakuhei has quit IRC | 20:12 | |
sigmavirus24 | I was looking for a way to have bandit only print files with a score greater than zero | 20:12 |
sigmavirus24 | If that's supposed to be -l then it doesn't work | 20:12 |
*** hyakuhei has joined #openstack-security | 20:12 | |
sigmavirus24 | I agree with most of Joe's points to be honest. I was going to work on slowly and iteratively improving them | 20:12 |
*** alex_klimov has joined #openstack-security | 20:12 | |
sigmavirus24 | I mean, the pastebin thing is whatever | 20:12 |
sigmavirus24 | I can show you projects where you can't pastebin the flake8 analysis either =P | 20:13 |
tmcpeak | I just ran it against Glance and it took about 30 seconds | 20:13 |
sigmavirus24 | o_O | 20:13 |
sigmavirus24 | How did you run it against glance? | 20:13 |
tmcpeak | bandit -r my_glance_directory | 20:14 |
sigmavirus24 | Yeah I ran it from a virtualenv but I'll time it this time | 20:14 |
tmcpeak | same, I'll pull the latest and time it | 20:14 |
sigmavirus24 | Oh I know what I did | 20:15 |
sigmavirus24 | I ran it against all of the glance projects (specs, glanceclient, glance, glance_store) | 20:15 |
browne | i'm around | 20:15 |
* sigmavirus24 recently restructured his projects folder so he has glance/api, glance/store, glance/client, glance/specs | 20:16 | |
tmcpeak | 31 seconds | 20:16 |
sigmavirus24 | tmcpeak: yep glance is only ~370 files so it's fast | 20:16 |
tmcpeak | ahh browne: I'm curious about Joe Gordon's comment that Bandit is slow | 20:16 |
sigmavirus24 | tmcpeak: run it against 7000 and it takes a while =P | 20:16 |
tmcpeak | well yeah ;) | 20:16 |
browne | it doesn't take that long for me | 20:16 |
browne | maybe 2 minutes max | 20:16 |
sigmavirus24 | huh, glanceclient is 6800 files? that seems wrong | 20:17 |
*** singleth_ has joined #openstack-security | 20:17 | |
tmcpeak | what are we running it against browne? | 20:17 |
browne | i meant with nova, ~800 | 20:17 |
tmcpeak | just nova? | 20:17 |
browne | so yeah, 6800 is probably slow | 20:17 |
browne | joe's comment was on my nova patch | 20:17 |
tmcpeak | sigmavirus24: why on earth is that 6800 Python files? ;) | 20:18 |
sigmavirus24 | tmcpeak: so if I give it the entire repository then it comes up as 6800 | 20:18 |
tmcpeak | browne: do you have the job that ran? or he ran it locally | 20:18 |
sigmavirus24 | If I scope it to the glanceclient directory it's fine | 20:18 |
browne | i ran locally | 20:18 |
tmcpeak | on just nova? | 20:18 |
browne | was planning to add the ci job later | 20:18 |
browne | just nova | 20:18 |
browne | let me run again now | 20:19 |
tmcpeak | 1444 files for Nova, timing now | 20:19 |
browne | 809 if you exclude tests and such | 20:19 |
browne | real1m10.225s | 20:20 |
browne | user1m8.717s | 20:20 |
browne | sys0m1.500s | 20:20 |
*** singlethink has quit IRC | 20:20 | |
browne | pretty quick | 20:20 |
sigmavirus24 | Now run flake8 against all of them ;) | 20:20 |
tmcpeak | yeah, 2m4s | 20:21 |
sigmavirus24 | I think flake8/hacking is Joe's typical point of reference | 20:21 |
tmcpeak | for the whole thing | 20:21 |
sigmavirus24 | That should finish in < 1 minute unless you're on an old version of flake8 without multiprocessing | 20:21 |
tmcpeak | sigmavirus24: yeah, makes sense | 20:21 |
*** dwyde has quit IRC | 20:21 | |
tmcpeak | still I think 1-2 mins is somewhat reasonable for a gate | 20:22 |
tmcpeak | tempest takes like.. weeks | 20:22 |
sigmavirus24 | tmcpeak: I don't disagree | 20:22 |
sigmavirus24 | The thing is if people are running this locally | 20:22 |
sigmavirus24 | 1-2 minutes is more than enough for me to get distracted and start doing something else only to completely forget what I was doing in that project in the first place | 20:22 |
tmcpeak | yeah, true.. but then you come back and remember you were doing your final local tests before pushing your code and heading out for a beer | 20:23 |
tmcpeak | I guess threading is the only real solution to pick up the speed | 20:23 |
tmcpeak | or exclude more | 20:24 |
sigmavirus24 | yeah I mean it isn't a huge deal to me | 20:24 |
sigmavirus24 | It's fast enough for most of the usecases that we care about | 20:24 |
tmcpeak | I'd like to address Joe's concerns though | 20:24 |
sigmavirus24 | So one thing that is probably super easy is to set a default threshold for when a file is printed to the screen | 20:25 |
sigmavirus24 | e.g., score > X | 20:25 |
sigmavirus24 | or >= | 20:25 |
browne | the -l does that | 20:25 |
sigmavirus24 | browne: didn't work for me recently | 20:25 |
browne | filters by severity | 20:25 |
tmcpeak | sigmavirus24: no? | 20:26 |
sigmavirus24 | unless the help docs are just wrong | 20:26 |
browne | i use -ll to get only medium and high | 20:26 |
sigmavirus24 | I used -l -l and it still printed everything | 20:26 |
sigmavirus24 | let me try -ll | 20:26 |
tmcpeak | yeah, -l is same as everything | 20:26 |
tmcpeak | -ll is medium high, -lll is only high | 20:26 |
tmcpeak | (I think) | 20:26 |
sigmavirus24 | Everything with score: 0 still appears for me | 20:27 |
browne | flake8 take around 30s | 20:27 |
browne | for me on nova | 20:27 |
sigmavirus24 | I'm running off of my entry-points branch though | 20:27 |
sigmavirus24 | So maybe I broke something somehow | 20:27 |
sigmavirus24 | Also, it seems we don't filter out *.pyc | 20:27 |
tmcpeak | sigmavirus24: no, pyc won't be included because it isn't in the included files type in the bandit profile | 20:28 |
*** dwyde has joined #openstack-security | 20:28 | |
sigmavirus24 | tmcpeak: right but it's printed in "Files excluded" | 20:28 |
sigmavirus24 | Which is extraordinarily annoying | 20:28 |
browne | yeah, that was a Joe complaint too | 20:29 |
browne | fine for a verbose switch | 20:29 |
tmcpeak | yeah, I guess we can suppress excluded files from default output | 20:29 |
browne | even included files is probably unnecessary by default | 20:30 |
tmcpeak | true | 20:30 |
tmcpeak | cool, yeah that should be an easy fix | 20:30 |
* sigmavirus24 leaves it as an exercise to the reader | 20:33 | |
* sigmavirus24 should get back to work | 20:33 | |
*** markvoelker has joined #openstack-security | 20:34 | |
tmcpeak | sigmavirus24: thanks man! | 20:35 |
sigmavirus24 | that or jsut file bugs and assign them to me | 20:35 |
sigmavirus24 | I'll get around to them eventually =P | 20:35 |
tmcpeak | I can take that one on | 20:37 |
tmcpeak | it's been a while since I've committed any code to Bandit, I think it's about tie | 20:38 |
tmcpeak | *time | 20:38 |
*** WaltBarnes has quit IRC | 20:38 | |
sigmavirus24 | There are a lot of people who've commited to bandit who don't have their emails linked to a github account | 20:38 |
sigmavirus24 | by their metrics I have the 2nd most number of commits in bandit | 20:38 |
*** markvoelker has quit IRC | 20:39 | |
tmcpeak | ;) gaming it | 20:40 |
*** singlethink has joined #openstack-security | 20:41 | |
*** singleth_ has quit IRC | 20:44 | |
sigmavirus24 | the stats are about the only thing I still like about GitHub | 20:46 |
*** localloop127 has joined #openstack-security | 20:51 | |
*** hyakuhei has quit IRC | 21:04 | |
*** localloop127 has quit IRC | 21:04 | |
openstackgerrit | Travis McPeak proposed stackforge/bandit: Adding verbose flag https://review.openstack.org/189941 | 21:06 |
*** hyakuhei has joined #openstack-security | 21:07 | |
tmcpeak | Bandit - less suck on output : https://review.openstack.org/#/c/189941/ | 21:07 |
sigmavirus24 | tmcpeak: ++ | 21:07 |
*** jian5397 has quit IRC | 21:08 | |
tmcpeak | sigmavirus24: waiting for your stuff too ;) | 21:08 |
tmcpeak | bknudson: ping | 21:19 |
bknudson | tmcpeak: what's up? | 21:20 |
tmcpeak | seems like you are attending these cross functional meetings anyway, would you mind representing security? hyakuhei asked me too, but a lot of this stuff is more "openstacky" then I have the knowledge for | 21:20 |
tmcpeak | *asked me to | 21:20 |
tmcpeak | maybe you can shout if something security related comes up that you don't know the answer to? | 21:21 |
tmcpeak | bknudson: ^ | 21:24 |
bknudson | tmcpeak: sure. | 21:24 |
openstackgerrit | Travis McPeak proposed stackforge/bandit: Adding verbose flag https://review.openstack.org/189941 | 21:24 |
tmcpeak | bknudson: awesome, thank you | 21:25 |
bknudson | tmcpeak: is there anything you want me to bring up? they have a section for cross-project announcements. | 21:25 |
bknudson | bandit progress? | 21:26 |
tmcpeak | bknudson: if anything maybe the developer guidelines would be good to sociallize | 21:27 |
tmcpeak | *socialize - no types today | 21:27 |
*** localloop127 has joined #openstack-security | 21:28 | |
bknudson | tmcpeak: we'll want to announce significant milestones like starting / initial and when complete. | 21:32 |
tmcpeak | ahh ok, on that page? | 21:32 |
tmcpeak | or in the meeting? | 21:32 |
bknudson | tmcpeak: in the cross-project meeting | 21:32 |
tmcpeak | bknudson: ok cool, makes sense. How major? | 21:33 |
tmcpeak | we should have a new pinned version of Bandit soon, we can announce that | 21:33 |
bknudson | that would probably be good enough for me to mention it at the meeting. | 21:33 |
tmcpeak | ok cool.. what's a good way to do this? I can just drop you notes when we have something good to say? | 21:34 |
bknudson | bring it up at the OSSG meeting | 21:34 |
tmcpeak | bknudson: ok cool - perfect | 21:34 |
browne | btw, will there be a OSSG mid-cycle? | 21:36 |
tmcpeak | browne: I'm pretty sure :) | 21:36 |
tmcpeak | yeah, I guess it's almost that time again, isn't it? | 21:36 |
browne | cool, thought the last was very productive | 21:36 |
tmcpeak | for sure, we got lots of good stuff done | 21:37 |
bknudson | nova and keystone are next month | 21:37 |
bknudson | and I think horizon and glance want to colocate with nova | 21:37 |
tmcpeak | how time flies! | 21:37 |
browne | nova is at IBM rochester | 21:37 |
browne | isn't that your home turf bknudson? | 21:38 |
bknudson | browne: y, it's in the building here. | 21:38 |
bknudson | so I should be able to stop in there and complain about security | 21:38 |
bknudson | rootwrap and stuff | 21:38 |
browne | cool! | 21:39 |
tmcpeak | lol | 21:39 |
tmcpeak | bknudson: btw, moved out to Montana for the summer.. drove through the very southern part of Minnesota - not super impressed | 21:39 |
browne | ha! | 21:40 |
tmcpeak | :P | 21:40 |
bknudson | tmcpeak: I90 is not exciting | 21:40 |
bknudson | except for the SPAM museum. | 21:40 |
tmcpeak | somehow TripAdvisor failed to bring that to my attention | 21:41 |
browne | do they have spam tastings? | 21:41 |
bknudson | of course | 21:41 |
browne | yum | 21:41 |
tmcpeak | actually it's beloved on TripAdvisor: http://www.tripadvisor.com/Attraction_Review-g29612-d126890-Reviews-Spam_Museum_and_Visitor_Center-Austin_Minnesota.html | 21:42 |
browne | oh, SPAM museum is closed till 2016. :( | 21:42 |
browne | crap, i missed the SPAMERICAN tour in San Fran | 21:44 |
tmcpeak | browne: :'( | 21:45 |
*** localloop127 has quit IRC | 22:04 | |
*** dwyde has quit IRC | 22:06 | |
*** bknudson has quit IRC | 22:13 | |
*** dwyde has joined #openstack-security | 22:19 | |
*** dwyde has quit IRC | 22:21 | |
*** singlethink has quit IRC | 22:25 | |
*** voodookid has quit IRC | 23:11 | |
openstackgerrit | Merged stackforge/bandit: Adding verbose flag https://review.openstack.org/189941 | 23:18 |
*** markvoelker has joined #openstack-security | 23:21 | |
*** markvoelker has quit IRC | 23:26 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!