*** pdesai has quit IRC | 00:03 | |
*** ccneill has quit IRC | 00:09 | |
*** jmckind has joined #openstack-security | 00:22 | |
*** bpokorny has quit IRC | 00:23 | |
*** austin987 has quit IRC | 00:26 | |
*** subscope has quit IRC | 00:35 | |
*** austin987 has joined #openstack-security | 00:40 | |
*** tjt263 has quit IRC | 00:40 | |
*** tjt263 has joined #openstack-security | 00:41 | |
*** tjt263 has quit IRC | 00:44 | |
*** tjt263 has joined #openstack-security | 00:45 | |
*** salv-orlando has quit IRC | 00:49 | |
*** browne has quit IRC | 01:56 | |
*** salv-orlando has joined #openstack-security | 01:57 | |
*** salv-orlando has quit IRC | 01:59 | |
*** salv-orlando has joined #openstack-security | 01:59 | |
*** yuanying_ has joined #openstack-security | 02:02 | |
*** edmondsw has quit IRC | 02:04 | |
*** yuanying has quit IRC | 02:05 | |
*** jmckind has quit IRC | 02:10 | |
*** yuanying_ has quit IRC | 02:11 | |
*** salv-orlando has quit IRC | 02:46 | |
*** yuanying has joined #openstack-security | 02:52 | |
*** jhfeng has joined #openstack-security | 02:53 | |
*** jamielennox is now known as jamielennox|away | 03:00 | |
*** jhfeng has quit IRC | 03:08 | |
*** jamielennox|away is now known as jamielennox | 03:10 | |
*** yuanying has quit IRC | 03:23 | |
*** jerrygb has quit IRC | 03:33 | |
*** jerrygb has joined #openstack-security | 03:34 | |
*** agireud has joined #openstack-security | 03:34 | |
*** agireud has quit IRC | 03:39 | |
*** agireud has joined #openstack-security | 03:41 | |
*** dave-mcc_ has quit IRC | 03:45 | |
*** salv-orlando has joined #openstack-security | 03:47 | |
*** salv-orlando has quit IRC | 03:52 | |
*** yuanying has joined #openstack-security | 04:07 | |
*** salv-orlando has joined #openstack-security | 04:48 | |
*** salv-orlando has quit IRC | 04:52 | |
*** jhfeng has joined #openstack-security | 05:06 | |
*** jhfeng has quit IRC | 05:10 | |
*** Ladillado has joined #openstack-security | 05:17 | |
*** Ladillado has quit IRC | 05:18 | |
*** jerrygb has quit IRC | 05:28 | |
*** jerrygb has joined #openstack-security | 05:29 | |
*** jerrygb has quit IRC | 05:33 | |
*** subscope has joined #openstack-security | 05:45 | |
*** jamielennox is now known as jamielennox|away | 06:29 | |
*** subscope has quit IRC | 06:32 | |
*** browne has joined #openstack-security | 06:57 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/243982 | 07:14 |
---|---|---|
*** jerrygb has joined #openstack-security | 07:30 | |
openstackgerrit | Merged openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/243982 | 07:31 |
*** jerrygb has quit IRC | 07:36 | |
*** jamielennox|away has quit IRC | 07:41 | |
*** whydidyoustealmy has joined #openstack-security | 07:42 | |
*** barra204 has quit IRC | 07:43 | |
*** liverpooler has joined #openstack-security | 07:45 | |
*** subscope has joined #openstack-security | 08:07 | |
*** alex_klimov has joined #openstack-security | 08:21 | |
*** jamielennox|away has joined #openstack-security | 08:31 | |
*** jamielennox|away is now known as jamielennox | 08:31 | |
*** Windir has joined #openstack-security | 08:37 | |
*** subscope has quit IRC | 08:52 | |
*** subscope has joined #openstack-security | 09:08 | |
*** browne has quit IRC | 09:09 | |
*** subscope has quit IRC | 09:46 | |
*** alex_klimov has quit IRC | 09:56 | |
*** subscope has joined #openstack-security | 09:58 | |
*** tjt263 has quit IRC | 10:20 | |
*** shohel has joined #openstack-security | 10:32 | |
*** alex_klimov has joined #openstack-security | 10:34 | |
*** markvoelker has quit IRC | 10:37 | |
*** subscope has quit IRC | 10:53 | |
*** subscope has joined #openstack-security | 10:53 | |
*** subscope has quit IRC | 11:14 | |
openstackgerrit | Tim Kelsey proposed openstack/bandit: Fixing bug when encountering tuple params https://review.openstack.org/244053 | 11:30 |
openstackgerrit | Tim Kelsey proposed openstack/bandit: Fixing bug when encountering tuple params https://review.openstack.org/244053 | 11:32 |
*** markvoelker has joined #openstack-security | 11:37 | |
*** markvoelker has quit IRC | 11:42 | |
*** shohel has quit IRC | 12:04 | |
*** subscope has joined #openstack-security | 12:05 | |
*** shohel has joined #openstack-security | 12:20 | |
*** shohel has quit IRC | 12:25 | |
*** openstackgerrit has quit IRC | 12:31 | |
*** openstackgerrit has joined #openstack-security | 12:31 | |
openstackgerrit | Tim Kelsey proposed openstack/bandit: os.system et al. all spawn a shell so we should use the same logic https://review.openstack.org/244075 | 12:36 |
*** jerrygb has joined #openstack-security | 12:37 | |
*** shohel has joined #openstack-security | 12:52 | |
*** markvoelker has joined #openstack-security | 12:53 | |
*** markvoelker has quit IRC | 12:58 | |
*** shohel has quit IRC | 13:03 | |
*** salv-orlando has joined #openstack-security | 13:03 | |
*** salv-orlando has quit IRC | 13:09 | |
*** edmondsw has joined #openstack-security | 13:31 | |
*** shohel has joined #openstack-security | 13:36 | |
*** shohel has quit IRC | 13:41 | |
*** dave-mccowan has joined #openstack-security | 13:41 | |
*** shohel has joined #openstack-security | 13:41 | |
*** Lalena has joined #openstack-security | 13:50 | |
*** shohel has quit IRC | 13:53 | |
*** subscope has quit IRC | 13:54 | |
*** markvoelker has joined #openstack-security | 13:54 | |
*** markvoelker has quit IRC | 13:58 | |
*** Lalena has quit IRC | 14:00 | |
*** agireud has quit IRC | 14:08 | |
*** subscope has joined #openstack-security | 14:13 | |
*** agireud has joined #openstack-security | 14:15 | |
*** markvoelker has joined #openstack-security | 14:15 | |
openstackgerrit | Tim Kelsey proposed openstack/bandit: os.system et al. all spawn a shell so we should use the same logic https://review.openstack.org/244075 | 14:29 |
*** shohel has joined #openstack-security | 14:29 | |
*** shohel1 has joined #openstack-security | 14:32 | |
*** shohel has quit IRC | 14:32 | |
*** tmcpeak has joined #openstack-security | 14:34 | |
*** shohel1 has quit IRC | 14:36 | |
*** shohel has joined #openstack-security | 14:43 | |
*** austin987 has quit IRC | 14:45 | |
*** jhfeng has joined #openstack-security | 15:10 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 15:27 | |
*** salv-orlando has joined #openstack-security | 15:38 | |
openstackgerrit | Merged openstack/security-doc: Adding Security Checklist https://review.openstack.org/240370 | 15:54 |
*** shohel has quit IRC | 15:57 | |
*** shohel has joined #openstack-security | 16:01 | |
*** openstackgerrit has quit IRC | 16:02 | |
*** openstackgerrit has joined #openstack-security | 16:02 | |
*** liverpooler has quit IRC | 16:02 | |
*** austin987 has joined #openstack-security | 16:12 | |
*** shohel has quit IRC | 16:12 | |
*** kun_huang_ has joined #openstack-security | 16:13 | |
*** subscope has quit IRC | 16:14 | |
*** subscope has joined #openstack-security | 16:15 | |
*** dlitz_ has joined #openstack-security | 16:16 | |
*** subscope has quit IRC | 16:16 | |
*** kun_huang has quit IRC | 16:17 | |
*** dlitz has quit IRC | 16:17 | |
*** subscope has joined #openstack-security | 16:17 | |
*** kun_huang_ is now known as kun_huang | 16:17 | |
*** salv-orlando has quit IRC | 16:23 | |
*** subscope has quit IRC | 16:27 | |
*** alex_klimov has quit IRC | 16:27 | |
*** subscope has joined #openstack-security | 16:29 | |
*** subscope has quit IRC | 16:30 | |
*** ccneill has joined #openstack-security | 16:33 | |
*** subscope has joined #openstack-security | 16:33 | |
*** bpokorny has joined #openstack-security | 16:58 | |
*** yeison has joined #openstack-security | 16:58 | |
*** yeison has left #openstack-security | 16:59 | |
*** pdesai has joined #openstack-security | 17:02 | |
*** salv-orlando has joined #openstack-security | 17:13 | |
*** subscope has quit IRC | 17:13 | |
*** subscope has joined #openstack-security | 17:33 | |
openstackgerrit | Travis McPeak proposed openstack/bandit: Changing issue candidates in baseline to ordered dict https://review.openstack.org/244247 | 17:34 |
*** subscope has quit IRC | 17:35 | |
*** markvoelker has quit IRC | 17:35 | |
openstackgerrit | Travis McPeak proposed openstack/bandit: Adding the Text Baseline Formatter https://review.openstack.org/242475 | 17:35 |
*** koon has joined #openstack-security | 17:36 | |
*** koon has quit IRC | 17:37 | |
openstackgerrit | Travis McPeak proposed openstack/bandit: Adding the Text Baseline Formatter https://review.openstack.org/242475 | 17:40 |
*** browne has joined #openstack-security | 17:44 | |
openstackgerrit | Travis McPeak proposed openstack/bandit: Adding the Text Baseline Formatter https://review.openstack.org/242475 | 17:56 |
*** markvoelker has joined #openstack-security | 18:31 | |
*** austin987 has quit IRC | 18:34 | |
*** austin987 has joined #openstack-security | 18:47 | |
*** ccneill has quit IRC | 19:00 | |
*** salv-orlando has quit IRC | 19:22 | |
*** lexholden has joined #openstack-security | 19:23 | |
*** salv-orlando has joined #openstack-security | 19:24 | |
openstackgerrit | Travis McPeak proposed openstack/bandit: Adding the Text Baseline Formatter https://review.openstack.org/242475 | 19:45 |
*** salv-orlando has quit IRC | 19:52 | |
*** salv-orlando has joined #openstack-security | 19:53 | |
*** salv-orlando has quit IRC | 19:58 | |
*** alex_klimov has joined #openstack-security | 20:09 | |
openstackgerrit | Travis McPeak proposed openstack/bandit: Adding the Text Baseline Formatter https://review.openstack.org/242475 | 20:13 |
*** lexholden has quit IRC | 20:19 | |
*** salv-orlando has joined #openstack-security | 20:39 | |
openstackgerrit | Travis McPeak proposed openstack/bandit: Adding the Text Baseline Formatter https://review.openstack.org/242475 | 20:48 |
openstackgerrit | Nathaniel Dillon proposed openstack/security-doc: Updating Bob's Case Studies - Tenant Data Privacy https://review.openstack.org/237369 | 20:49 |
openstackgerrit | Travis McPeak proposed openstack/bandit: Adding HTML baseline formatter https://review.openstack.org/244307 | 20:49 |
tmcpeak | browne: can you do some reviews? | 20:51 |
tmcpeak | first this: https://review.openstack.org/244247 | 20:51 |
tmcpeak | then this: https://review.openstack.org/242475 | 20:51 |
tmcpeak | then this: https://review.openstack.org/244307 | 20:51 |
*** sigmavirus24 is now known as sigmavirus24_awa | 21:03 | |
browne | tmcpeak: sure | 21:13 |
tmcpeak | browne: awesome, thank you | 21:14 |
*** jhfeng has quit IRC | 21:16 | |
*** jhfeng has joined #openstack-security | 21:18 | |
browne | tmcpeak: could you explain the baseline formatters more to me. not sure i understand how or what these are for | 21:20 |
tmcpeak | sure - so with baseline our new approach is to pair down all the issues | 21:20 |
tmcpeak | so if we had 2 insecure tmps in a file and now we have 3, we'll say one is the new issue | 21:21 |
tmcpeak | but we don't know which one | 21:21 |
tmcpeak | so the baseline formatter will show candidate issues in the case where it can't match which is the new issue | 21:21 |
browne | oh, its a delta from a previous run somehow? | 21:21 |
tmcpeak | yeah, it compares to a JSON output that was taken on a previous run | 21:21 |
tmcpeak | I've got a gate that will automatically do it based on the parent commit that I'll be upstreaming soon | 21:22 |
*** salv-orlando has quit IRC | 21:22 | |
browne | but so it shows the issue, but not the line number? | 21:23 |
tmcpeak | it makes a list of issues with corresponding candidates | 21:23 |
tmcpeak | if there is only 1 candidate for an issue, it just shows it normally | 21:23 |
tmcpeak | if there are 2+ candidates it shows the issue without the code and then the code blocks where it could be | 21:23 |
tmcpeak | if you want to play with it, do this | 21:24 |
tmcpeak | create some code, run bandit code.py -f json -o baseline.json | 21:24 |
browne | ha, was just about to ask | 21:24 |
tmcpeak | then add some issues | 21:24 |
tmcpeak | run bandit.py -b baseline.json | 21:24 |
tmcpeak | you'll see just the issues you've added | 21:24 |
tmcpeak | if one of the is the same issue category you already had in there, you'll see candidates | 21:25 |
*** salv-orlando has joined #openstack-security | 21:25 | |
browne | thx, i'll play with it | 21:26 |
tmcpeak | cool, sounds good | 21:26 |
tmcpeak | browne: you might as well synch the HTML formatter, the output is cool (if I do say so myself) | 21:27 |
browne | alright | 21:27 |
openstackgerrit | Merged openstack/bandit: Fixing bug when encountering tuple params https://review.openstack.org/244053 | 21:42 |
*** subscope has joined #openstack-security | 21:57 | |
*** subscope has quit IRC | 22:02 | |
*** alex_klimov has quit IRC | 22:08 | |
*** salv-orlando has quit IRC | 22:13 | |
*** jhfeng has quit IRC | 22:19 | |
*** jhfeng has joined #openstack-security | 22:21 | |
*** jhfeng has quit IRC | 22:22 | |
*** jhfeng has joined #openstack-security | 22:22 | |
*** edmondsw has quit IRC | 22:23 | |
*** tmcpeak has quit IRC | 22:39 | |
openstackgerrit | Merged openstack/bandit: Changing issue candidates in baseline to ordered dict https://review.openstack.org/244247 | 22:39 |
openstackgerrit | Merged openstack/security-doc: Updating Bob's Case Studies - Tenant Data Privacy https://review.openstack.org/237369 | 22:39 |
*** ccneill has joined #openstack-security | 23:26 | |
*** jhfeng has quit IRC | 23:41 | |
*** sicarie has quit IRC | 23:47 | |
*** ccneill has quit IRC | 23:56 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!