*** sdake has quit IRC | 00:29 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 00:58 | |
*** elo has joined #openstack-security | 01:10 | |
*** elo1 has joined #openstack-security | 01:10 | |
*** elo2 has quit IRC | 01:13 | |
*** elo has quit IRC | 01:14 | |
*** tmcpeak has quit IRC | 01:24 | |
*** hyakuhei has quit IRC | 01:31 | |
*** hyakuhei has joined #openstack-security | 01:41 | |
*** elo1 has quit IRC | 01:44 | |
*** sdake has joined #openstack-security | 02:11 | |
*** elo has joined #openstack-security | 02:32 | |
*** jian5397 has joined #openstack-security | 02:38 | |
*** elo has quit IRC | 02:43 | |
*** hyakuhei has quit IRC | 03:44 | |
*** hyakuhei has joined #openstack-security | 03:45 | |
*** elo has joined #openstack-security | 03:47 | |
*** tmcpeak has joined #openstack-security | 03:50 | |
*** dave-mccowan has quit IRC | 04:09 | |
*** jian5397 has quit IRC | 04:15 | |
*** jian5397 has joined #openstack-security | 04:19 | |
*** jian5397 has quit IRC | 04:33 | |
*** browne1 has joined #openstack-security | 04:40 | |
*** browne has quit IRC | 04:40 | |
*** tmcpeak has quit IRC | 05:51 | |
openstackgerrit | Stanislaw Pitucha proposed stackforge/anchor: Implement saving certificate in memory https://review.openstack.org/197433 | 06:17 |
---|---|---|
*** shohel has joined #openstack-security | 06:20 | |
*** browne1 has quit IRC | 06:21 | |
openstackgerrit | Stanislaw Pitucha proposed stackforge/anchor: Implement saving certificate in memory https://review.openstack.org/197433 | 06:24 |
*** elo1 has joined #openstack-security | 08:04 | |
*** elo1 has joined #openstack-security | 08:04 | |
*** elo has quit IRC | 08:08 | |
*** elo1 has quit IRC | 08:12 | |
*** shohel has quit IRC | 08:31 | |
*** shohel has joined #openstack-security | 08:31 | |
*** jian5397 has joined #openstack-security | 09:16 | |
*** elo has joined #openstack-security | 09:37 | |
*** jian5397 has quit IRC | 09:40 | |
*** jian5397 has joined #openstack-security | 09:43 | |
*** shohel has quit IRC | 09:43 | |
*** shohel has joined #openstack-security | 09:44 | |
*** sdake has quit IRC | 09:46 | |
*** jian5397 has joined #openstack-security | 09:48 | |
*** jian5397 has quit IRC | 10:00 | |
openstackgerrit | Tim Kelsey proposed stackforge/bandit: Adding a test for partial paths in exec functions https://review.openstack.org/197180 | 10:07 |
openstackgerrit | Merged stackforge/anchor: Update documentation https://review.openstack.org/190503 | 10:57 |
*** rmarathu has joined #openstack-security | 12:12 | |
*** dave-mccowan has joined #openstack-security | 12:13 | |
*** markvoelker has quit IRC | 12:14 | |
rmarathu | Hi all, anybody has any idea on bandit tool - security code analyzer? I would like to start using that and any inputs would be great on that? we are using RATS now and how beneficial to use Bandit against RATS? thanks in advance | 12:14 |
*** markvoelker has joined #openstack-security | 12:14 | |
*** raginbajin has quit IRC | 12:18 | |
*** raginbajin has joined #openstack-security | 12:19 | |
*** edmondsw has joined #openstack-security | 12:32 | |
*** bknudson has joined #openstack-security | 12:45 | |
*** singlethink has joined #openstack-security | 12:59 | |
*** vivcheri has joined #openstack-security | 13:10 | |
elmiko | rmarathu: hi, i'd start with the bandit wiki page and then work through the documentation, https://wiki.openstack.org/wiki/Security/Projects/Bandit | 13:19 |
rmarathu | elmiko: hi and thank you for the update. I will check... | 13:22 |
*** browne has joined #openstack-security | 13:28 | |
*** tmcpeak has joined #openstack-security | 13:53 | |
*** jian5397 has joined #openstack-security | 13:57 | |
*** jian5397 has quit IRC | 14:12 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 14:12 | |
*** jian5397 has joined #openstack-security | 14:12 | |
*** localloop127 has joined #openstack-security | 14:17 | |
*** jian5397 has left #openstack-security | 14:27 | |
*** jian5397 has joined #openstack-security | 14:29 | |
*** jian5397 has quit IRC | 14:30 | |
*** voodookid has joined #openstack-security | 14:35 | |
*** serverascode_ has joined #openstack-security | 14:39 | |
*** gmurphy_ has joined #openstack-security | 14:46 | |
*** woodrow has quit IRC | 14:46 | |
*** serverascode has quit IRC | 14:46 | |
*** gmurphy has quit IRC | 14:46 | |
*** jian5397 has joined #openstack-security | 14:49 | |
*** shohel has quit IRC | 14:54 | |
*** serverascode_ is now known as serverascode | 14:56 | |
*** dwyde has joined #openstack-security | 15:00 | |
*** woodrow has joined #openstack-security | 15:04 | |
sigmavirus24 | Congrats elmiko and tmcpeak | 15:12 |
tmcpeak | sigmavirus24: thank you :) | 15:12 |
elmiko | sigmavirus24: tnx =) | 15:12 |
* sigmavirus24 does not envy either of you | 15:15 | |
elmiko | lol | 15:16 |
*** shohel has joined #openstack-security | 15:17 | |
*** shohel has quit IRC | 15:17 | |
sigmavirus24 | I'm a security core reviewer for os-ansible-deployment (soon to be openstack-ansible) and while it hasn't been a high traffic position, it is a bit stressful | 15:17 |
tmcpeak | sigmavirus24: I believe that ;) | 15:17 |
sigmavirus24 | Also, I'm now really going to insist on adding bandit to glance's gate | 15:17 |
tmcpeak | +1 | 15:17 |
sigmavirus24 | Because someone just told someone else to use eval in parsing user input | 15:18 |
sigmavirus24 | And I got mad | 15:18 |
tmcpeak | haha, seems legit | 15:18 |
sigmavirus24 | glance currently has no bandit issues | 15:19 |
*** jian5397 has quit IRC | 15:19 | |
tmcpeak | ahh cool, a good time to inject it in the gate then :) | 15:20 |
sigmavirus24 | Yep | 15:36 |
openstackgerrit | Michael McCune proposed openstack/security-doc: Add OSSN-0049 https://review.openstack.org/194416 | 15:40 |
elmiko | do you guys know what channel the devstack folks hangout in? | 15:43 |
*** singlethink has quit IRC | 15:44 | |
sigmavirus24 | elmiko: in #openstack-infra or #openstack-qa | 15:45 |
elmiko | sigmavirus24: cool, thanks! | 15:45 |
sigmavirus24 | elmiko: I think dtroyer is everywhere though | 15:45 |
elmiko | haha | 15:45 |
sigmavirus24 | also sdague | 15:45 |
elmiko | ok, didn't realize they are the main contacts for devstack | 15:46 |
*** jian5397 has joined #openstack-security | 15:46 | |
openstackgerrit | Michael McCune proposed openstack/security-doc: Add OSSN-0049 https://review.openstack.org/194416 | 15:49 |
elmiko | thanks tmcpeak ;) | 15:49 |
tmcpeak | elmiko: sure, other than that it looks good | 15:50 |
elmiko | cool, it's all details at this point lol | 15:50 |
*** elo1 has joined #openstack-security | 15:57 | |
*** elo has quit IRC | 16:01 | |
*** rmarathu has quit IRC | 16:01 | |
*** singlethink has joined #openstack-security | 16:05 | |
*** dwyde has left #openstack-security | 16:06 | |
*** sdake has joined #openstack-security | 16:24 | |
*** singleth_ has joined #openstack-security | 16:53 | |
*** singlethink has quit IRC | 16:57 | |
*** browne has quit IRC | 17:02 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 17:04 | |
*** sdake_ has joined #openstack-security | 17:18 | |
*** sdake has quit IRC | 17:21 | |
*** sdake_ is now known as sdake | 17:39 | |
*** dwyde has joined #openstack-security | 17:43 | |
*** sdake has quit IRC | 17:44 | |
*** singlethink has joined #openstack-security | 17:45 | |
*** browne has joined #openstack-security | 17:45 | |
*** sdake has joined #openstack-security | 17:46 | |
*** singlet__ has joined #openstack-security | 17:48 | |
*** singleth_ has quit IRC | 17:48 | |
*** sdake has quit IRC | 17:48 | |
*** sdake has joined #openstack-security | 17:49 | |
*** singlethink has quit IRC | 17:51 | |
*** deepika has joined #openstack-security | 17:53 | |
*** browne has quit IRC | 18:01 | |
*** browne has joined #openstack-security | 18:02 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 18:06 | |
*** sdake has quit IRC | 18:38 | |
*** sdake has joined #openstack-security | 18:38 | |
*** sdake_ has joined #openstack-security | 18:41 | |
*** sdake has quit IRC | 18:44 | |
*** jian5397 has quit IRC | 19:03 | |
*** singlethink has joined #openstack-security | 19:15 | |
*** singlet__ has quit IRC | 19:18 | |
*** sdake has joined #openstack-security | 19:21 | |
*** sdake has quit IRC | 19:23 | |
*** sdake has joined #openstack-security | 19:23 | |
*** sdake_ has quit IRC | 19:25 | |
*** elo1 has quit IRC | 19:31 | |
*** singlethink has quit IRC | 19:35 | |
sigmavirus24 | tmcpeak: chair6 should the midcycle schedule be on https://wiki.openstack.org/wiki/Sprints ? | 19:48 |
tmcpeak | sigmavirus24: yeah, for sure | 19:48 |
tmcpeak | maybe attract some more folks | 19:48 |
*** singlethink has joined #openstack-security | 19:56 | |
*** vivcheri has quit IRC | 20:02 | |
*** deepika has quit IRC | 20:19 | |
*** openstackgerrit has quit IRC | 20:37 | |
*** openstackgerrit has joined #openstack-security | 20:37 | |
openstackgerrit | Priti Desai proposed openstack/security-specs: Initial Security Specs Repo https://review.openstack.org/197735 | 20:55 |
elmiko | tmcpeak: would you mind taking a look at nkinder's comments on https://review.openstack.org/#/c/194416/ | 21:01 |
*** sdake_ has joined #openstack-security | 21:07 | |
*** sdake has quit IRC | 21:09 | |
openstackgerrit | Priti Desai proposed openstack/security-specs: Setup Security Specs Repo https://review.openstack.org/197735 | 21:27 |
*** edmondsw has quit IRC | 21:28 | |
*** bknudson has quit IRC | 21:51 | |
*** elo has joined #openstack-security | 21:53 | |
*** singleth_ has joined #openstack-security | 21:56 | |
*** localloop127 has quit IRC | 21:59 | |
*** singlethink has quit IRC | 21:59 | |
*** sdake_ is now known as sdake | 22:17 | |
*** dwyde has quit IRC | 22:27 | |
*** sdake is now known as sdake_ | 22:29 | |
*** singleth_ has quit IRC | 22:30 | |
tmcpeak | elmiko: sure | 22:40 |
openstackgerrit | Priti Desai proposed openstack/security-specs: Setup Security Specs Repo https://review.openstack.org/197735 | 22:41 |
elmiko | thanks, he brought a good point about including the code patch | 22:41 |
tmcpeak | yeah, I know we went back and forth on that. I think it's good to include for completeness, especially since upgrades can be so painful | 22:41 |
tmcpeak | nkinder: you around? | 22:42 |
nkinder | tmcpeak: yep | 22:42 |
elmiko | agreed, contentious issue ;) | 22:42 |
tmcpeak | so yeah, on that OSSN, I recommended we add it just for people running now unsupported versions, like IceHouse | 22:42 |
nkinder | tmcpeak: any issue that has a fix can be manually backported. I'm just not sure we want to call it out for operators as a recommendation. | 22:42 |
*** browne has quit IRC | 22:43 | |
tmcpeak | for sure, but it won't be backported because of the 3 release support window | 22:43 |
tmcpeak | what about if we call it out with a big old disclaimer? | 22:43 |
nkinder | It's all too easy to mess something up, or to have unintended consequences. | 22:43 |
nkinder | This fix is easy, but it still sets a precedent | 22:44 |
tmcpeak | yeah, I see what you're saying | 22:44 |
tmcpeak | hmm, yeah, I guess unsupported is unsupported for a reason, people haven't had time to do proper testing | 22:44 |
nkinder | tmcpeak: the OSSN has a link to the bug, where they can see the code for fixes | 22:45 |
tmcpeak | you're right, I guess we should remove it. If anybody is adventurous enough to patch it themselves they can certainly find it | 22:45 |
nkinder | if they want to go down that path, we give them enough rope to hang themselves with IMHO :) | 22:45 |
elmiko | hehe | 22:45 |
tmcpeak | cool, yeah, good points. I'm flip-flopping and now agree with you | 22:45 |
elmiko | ok, so i can just drop the whole para+patch about fixing the code? | 22:45 |
tmcpeak | yeah, sorry elmiko - I've created more work for you (again) | 22:46 |
elmiko | tmcpeak: no worries, i'm in for the long haul ;) | 22:46 |
tmcpeak | haha ok cool ;) | 22:46 |
openstackgerrit | Michael McCune proposed openstack/security-doc: Add OSSN-0049 https://review.openstack.org/194416 | 22:49 |
elmiko | et viola | 22:49 |
nkinder | elmiko: awesome. LGTM | 22:51 |
elmiko | thanks for all the help guys =) | 22:52 |
tmcpeak | elmiko: great job | 22:53 |
*** sdake_ has quit IRC | 22:54 | |
*** voodookid has quit IRC | 23:02 | |
*** browne has joined #openstack-security | 23:39 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!