*** jhfeng has quit IRC | 00:01 | |
browne | tmcpeak: yep, i'm here | 00:12 |
---|---|---|
tmcpeak | browne: hmm, nevermind (sorry) am trying to come up with a good way to get a Bandit version released with this .bandit feature that won't move backwards in current functionality | 00:16 |
tmcpeak | seems like blacklist doesn't allow selective enabling/disabling right now which is a regression | 00:16 |
browne | ok np | 00:16 |
*** salv-orl_ has quit IRC | 00:17 | |
tmcpeak | was debating the merits of maybe going to 0.17.0, cherry picking .bandit change, and rolling a 0.17.1 from that, but let me see how far Tim is from getting selective blacklist running first | 00:17 |
browne | i'm fine wth a 0.17.1 | 00:17 |
browne | or a 0.18 | 00:17 |
tmcpeak | the only strange part about it would be that it's literally just 0.17.0 with the .bandit change, so we'd be leaving off all other new changes | 00:18 |
tmcpeak | or maybe 0.17.0 + docs and other non-functionality modifying stuff | 00:18 |
browne | oh i see | 00:18 |
tmcpeak | we haven't really done that before | 00:18 |
tmcpeak | we also haven't really been in a halfway state before, but we're trying to do a bunch of big stuff to get config fixed, so I dunno | 00:18 |
browne | so the 0.17.1 to avoid a breaking change? | 00:18 |
browne | in any case, any newer version would get picked up by all other projects | 00:19 |
*** jmckind has joined #openstack-security | 00:20 | |
tmcpeak | browne: right, so basically the 0.17.1 is exactly what's on PyPI now with that one piece of new non-breaking functionality | 00:21 |
tmcpeak | is that janky or reasonable? or somewhere in between | 00:21 |
browne | i think that might be fine, but let's get input from the other cores | 00:22 |
tmcpeak | ok cool, sounds like a plan | 00:22 |
*** jmckind_ has quit IRC | 00:23 | |
*** jmckind_ has joined #openstack-security | 00:25 | |
*** jmckind has quit IRC | 00:28 | |
*** tmcpeak has quit IRC | 00:29 | |
*** yuanying has joined #openstack-security | 01:10 | |
*** yuanying_ has quit IRC | 01:11 | |
*** salv-orlando has joined #openstack-security | 01:17 | |
*** salv-orlando has quit IRC | 01:20 | |
*** bpokorny has quit IRC | 01:38 | |
*** austin987 has quit IRC | 01:41 | |
*** austin987 has joined #openstack-security | 01:53 | |
*** salv-orlando has joined #openstack-security | 01:54 | |
*** salv-orlando has quit IRC | 01:59 | |
*** yuanying has quit IRC | 02:00 | |
*** yuanying has joined #openstack-security | 02:03 | |
*** salv-orlando has joined #openstack-security | 02:19 | |
*** yuanying has quit IRC | 02:25 | |
*** salv-orlando has quit IRC | 02:27 | |
*** yuanying has joined #openstack-security | 02:27 | |
*** salv-orlando has joined #openstack-security | 02:41 | |
*** salv-orlando has quit IRC | 02:48 | |
*** superflyy has joined #openstack-security | 02:50 | |
*** jmckind has joined #openstack-security | 03:04 | |
*** jmckind_ has quit IRC | 03:07 | |
*** jmckind_ has joined #openstack-security | 03:10 | |
*** jmckind has quit IRC | 03:13 | |
*** browne has quit IRC | 03:15 | |
*** yuanying_ has joined #openstack-security | 03:19 | |
*** yuanyin__ has joined #openstack-security | 03:20 | |
*** yuanying has quit IRC | 03:22 | |
*** yuanying_ has quit IRC | 03:23 | |
*** yuanyin__ has quit IRC | 03:29 | |
*** yuanying has joined #openstack-security | 03:29 | |
*** ccneill has quit IRC | 03:44 | |
*** yuanying has quit IRC | 03:57 | |
*** yuanying has joined #openstack-security | 03:58 | |
*** superflyy has quit IRC | 04:01 | |
*** yuanying has quit IRC | 04:02 | |
*** browne has joined #openstack-security | 04:05 | |
*** yuanying has joined #openstack-security | 04:08 | |
*** dave-mccowan has quit IRC | 04:50 | |
*** redrobot has left #openstack-security | 06:26 | |
*** redrobot has joined #openstack-security | 06:27 | |
*** salv-orlando has joined #openstack-security | 06:38 | |
*** austin987 has quit IRC | 06:39 | |
*** austin987 has joined #openstack-security | 06:41 | |
*** salv-orlando has quit IRC | 06:42 | |
*** rcernin has joined #openstack-security | 06:53 | |
*** salv-orlando has joined #openstack-security | 06:56 | |
*** jmckind_ has quit IRC | 06:58 | |
*** salv-orlando has quit IRC | 07:46 | |
*** liverpooler has joined #openstack-security | 07:54 | |
*** austin987 has quit IRC | 08:06 | |
*** austin987 has joined #openstack-security | 08:10 | |
*** salv-orlando has joined #openstack-security | 08:47 | |
*** salv-orlando has quit IRC | 09:01 | |
*** salv-orlando has joined #openstack-security | 09:03 | |
*** browne has quit IRC | 09:14 | |
*** markvoelker has quit IRC | 09:23 | |
*** salv-orl_ has joined #openstack-security | 10:06 | |
*** salv-orlando has quit IRC | 10:08 | |
*** jamielennox is now known as jamielennox|away | 10:15 | |
*** markvoelker has joined #openstack-security | 10:23 | |
*** jamielennox|away is now known as jamielennox | 10:25 | |
*** markvoelker has quit IRC | 10:28 | |
*** salv-orl_ has quit IRC | 10:45 | |
*** salv-orlando has joined #openstack-security | 11:01 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/272486 | 11:45 |
openstackgerrit | Merged openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/272486 | 11:54 |
*** backendbeemo has joined #openstack-security | 11:57 | |
*** backendbeemo has left #openstack-security | 11:57 | |
*** salv-orlando has quit IRC | 12:11 | |
*** salv-orlando has joined #openstack-security | 12:13 | |
*** backendbeemo has joined #openstack-security | 12:16 | |
*** backendbeemo has left #openstack-security | 12:16 | |
*** markvoelker has joined #openstack-security | 12:25 | |
*** markvoelker has quit IRC | 12:29 | |
*** salv-orlando has quit IRC | 12:57 | |
openstackgerrit | Tim Kelsey proposed openstack/bandit: This permits blacklist data to be filtered by ID https://review.openstack.org/272520 | 13:15 |
*** edmondsw has joined #openstack-security | 13:18 | |
*** markvoelker has joined #openstack-security | 13:25 | |
*** markvoelker has quit IRC | 13:28 | |
*** markvoelker has joined #openstack-security | 13:28 | |
*** dave-mccowan has joined #openstack-security | 13:35 | |
*** ninag has joined #openstack-security | 13:42 | |
*** salv-orlando has joined #openstack-security | 13:58 | |
*** salv-orlando has quit IRC | 14:03 | |
openstackgerrit | Tim Kelsey proposed openstack/bandit: This permits blacklist data to be filtered by ID https://review.openstack.org/272520 | 14:05 |
openstackgerrit | Tim Kelsey proposed openstack/bandit: This permits blacklist data to be filtered by ID https://review.openstack.org/272520 | 14:17 |
*** yarkot has quit IRC | 14:35 | |
*** edtubill has joined #openstack-security | 14:36 | |
openstackgerrit | Tim Kelsey proposed openstack/bandit: This permits blacklist data to be filtered by ID https://review.openstack.org/272520 | 14:38 |
*** salv-orlando has joined #openstack-security | 14:54 | |
*** salv-orlando has quit IRC | 14:57 | |
*** jhfeng has joined #openstack-security | 15:06 | |
*** jmckind has joined #openstack-security | 15:08 | |
*** salv-orlando has joined #openstack-security | 15:10 | |
*** salv-orlando has quit IRC | 15:11 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 15:11 | |
*** salv-orlando has joined #openstack-security | 15:11 | |
*** tmcpeak has joined #openstack-security | 15:13 | |
*** jmckind_ has joined #openstack-security | 15:13 | |
*** jmckind has quit IRC | 15:16 | |
*** salv-orlando has quit IRC | 15:34 | |
*** salv-orlando has joined #openstack-security | 15:35 | |
*** salv-orl_ has joined #openstack-security | 16:06 | |
*** salv-orlando has quit IRC | 16:09 | |
*** austin987 has quit IRC | 16:11 | |
openstackgerrit | Tim Kelsey proposed openstack/bandit: Old config compatibility https://review.openstack.org/272620 | 16:18 |
*** avarner has quit IRC | 16:20 | |
*** austin987 has joined #openstack-security | 16:27 | |
openstackgerrit | Tim Kelsey proposed openstack/bandit: Old config compatibility https://review.openstack.org/272620 | 16:28 |
*** avarner has joined #openstack-security | 16:28 | |
*** avarner_ has joined #openstack-security | 16:34 | |
*** avarner__ has joined #openstack-security | 16:36 | |
*** avarner has quit IRC | 16:36 | |
*** avarner_ has quit IRC | 16:39 | |
*** avarner has joined #openstack-security | 16:41 | |
*** avarner__ has quit IRC | 16:43 | |
*** diazjf has joined #openstack-security | 16:44 | |
*** browne has joined #openstack-security | 16:44 | |
*** cjschaef has joined #openstack-security | 16:58 | |
*** ccneill has joined #openstack-security | 16:58 | |
*** diazjf has quit IRC | 17:03 | |
*** diazjf1 has joined #openstack-security | 17:03 | |
*** bpokorny has joined #openstack-security | 17:06 | |
*** tmcpeak has quit IRC | 17:08 | |
*** openstackgerrit has quit IRC | 17:17 | |
*** openstackgerrit has joined #openstack-security | 17:17 | |
*** c00p3r has quit IRC | 17:28 | |
*** c00p3r has joined #openstack-security | 17:34 | |
*** hockeynut is now known as hockeynut_otr | 17:51 | |
*** diazjf1 has quit IRC | 17:52 | |
*** hockeynut_otr is now known as hockeynut | 17:52 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 17:59 | |
*** hockeynut_afk has joined #openstack-security | 18:00 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 18:03 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 18:04 | |
*** hockeynut_afk has quit IRC | 18:05 | |
*** hockeynut_otr has joined #openstack-security | 18:06 | |
*** tmcpeak has joined #openstack-security | 18:06 | |
*** hockeynut_otr has quit IRC | 18:28 | |
*** jmckind_ has quit IRC | 18:46 | |
tmcpeak | browne: ok, after talking with Tim I think we'll go with 0.17.1 with just the new .bandit function in it | 18:46 |
tmcpeak | sound reasonable? | 18:46 |
tmcpeak | there's too much in flight right now to do a half way release I think, and these teams I'm working with really need .bandit | 18:47 |
browne | ok sounds good | 18:47 |
tmcpeak | cool | 18:47 |
tmcpeak | I'm doing some sanity checking now, should be releasing very soon | 18:47 |
*** jmckind has joined #openstack-security | 18:48 | |
*** avarner has quit IRC | 18:49 | |
*** browne has quit IRC | 18:50 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 18:57 | |
*** diazjf has joined #openstack-security | 18:58 | |
*** ninag has quit IRC | 18:59 | |
*** ninag has joined #openstack-security | 19:02 | |
sigmavirus24 | tmcpeak: semantically speaking, if we're going to support the new .bandit config file, that should be 0.18.0 | 19:13 |
sigmavirus24 | unless we were advertising support for that in 0.17.0 and that support was broken | 19:13 |
tmcpeak | sigmavirus24: hmm, yeah, solid point | 19:13 |
tmcpeak | however… I already pushed 0.17.1 :# | 19:14 |
sigmavirus24 | tmcpeak: oh well | 19:14 |
sigmavirus24 | :P | 19:14 |
sigmavirus24 | Don't let our release overlords know :P | 19:14 |
tmcpeak | sigmavirus24: I do want to do proper numbering so I'll bounce off you next time | 19:14 |
sigmavirus24 | tmcpeak: also, speaking of release overlords, they want all projects (even ones they don't manage releases of) tracked in the releases repository | 19:14 |
sigmavirus24 | We should probably send a change (or however many) with release info for that | 19:14 |
tmcpeak | what's that entail? | 19:15 |
* sigmavirus24 doesn't know | 19:15 | |
* sigmavirus24 just saw Doug's email to [all] on -dev | 19:15 | |
sigmavirus24 | I suspect that dhellman could answer in #openstack-release tmcpeak | 19:15 |
tmcpeak | cool | 19:15 |
tmcpeak | I'll read it too | 19:15 |
tmcpeak | why isn't my annotated tag automatically causing upload of 0.17.1 to PyPI | 19:16 |
tmcpeak | that's the question of the day | 19:16 |
Ryan_Lane | so, with the unreleased version of bandit, it won't run checks that don't have a test id, right? | 19:18 |
Ryan_Lane | but the older version doesn't have the decorator needed to add test ids | 19:18 |
Ryan_Lane | maybe for one version it would be a good idea to not require test ids, so that there's at least one release of compatible plugins | 19:19 |
*** ccneill has quit IRC | 19:19 | |
Ryan_Lane | or backport the decorator | 19:19 |
*** ninag has quit IRC | 19:21 | |
*** ninag has joined #openstack-security | 19:21 | |
*** ninag has quit IRC | 19:22 | |
tmcpeak | Ryan_Lane: solid point | 19:22 |
*** ninag has joined #openstack-security | 19:22 | |
tmcpeak | Ryan_Lane: would you mind filing that on Launchpad? I don't want that to get dropped | 19:22 |
Ryan_Lane | ideally backport the decorator :) | 19:22 |
Ryan_Lane | sigh launchpad | 19:22 |
tmcpeak | ahh come on, everybody loves launchpad | 19:22 |
Ryan_Lane | I can't believe you folks are _still_ using launchpad for bugs | 19:22 |
Ryan_Lane | I hate logging into it so much | 19:22 |
tmcpeak | what are you using? | 19:23 |
Ryan_Lane | jira, github, phabricator (depending on the project) | 19:23 |
tmcpeak | feels speedier to me than Jira | 19:24 |
Ryan_Lane | it isn't :( | 19:24 |
tmcpeak | PyPI what can't I haz 0.17.1?! | 19:26 |
*** browne has joined #openstack-security | 19:27 | |
Ryan_Lane | the new version that requires the test decorator is going to be 0.17.1? | 19:30 |
Ryan_Lane | and the one that doesn't is 0.17.0? | 19:30 |
*** bpokorny_ has joined #openstack-security | 19:30 | |
Ryan_Lane | if so, it should be 0.18.0, right? | 19:30 |
*** bpokorny_ has quit IRC | 19:31 | |
*** bpokorny_ has joined #openstack-security | 19:31 | |
*** ccneill has joined #openstack-security | 19:32 | |
tmcpeak | Ryan_Lane: no, 0.17.0 has been released for a long time, 0.17.1 is a specific release just to support this one feature one of the teams I work with needs, 0.18.0/1.0 are future releases | 19:33 |
tmcpeak | I suspect 0.18.0 will be where we can release forward looking things | 19:33 |
Ryan_Lane | ah. ok. so 0.17.1 won't have the breaking change? | 19:33 |
tmcpeak | like the test ID decorator | 19:33 |
Ryan_Lane | cool | 19:33 |
tmcpeak | yeah, 0.17.1 doesn't have anything except this *one* .bandit feature. No breaking changes | 19:34 |
*** bpokorny has quit IRC | 19:34 | |
tmcpeak | Ryan_Lane: thanks for LP bug | 19:37 |
Ryan_Lane | yw | 19:39 |
Ryan_Lane | was there ever a bug opened about being able to disable specific test numbers? | 19:40 |
Ryan_Lane | like # no-sec-b100 | 19:40 |
*** ninag has quit IRC | 19:44 | |
*** ninag has joined #openstack-security | 19:45 | |
Ryan_Lane | well, if not, there's one now :) | 19:46 |
*** salv-orl_ has quit IRC | 19:46 | |
tmcpeak | Ryan_Lane: awesome | 19:49 |
tmcpeak | I think Stan was working on some nosec stuff | 19:50 |
tmcpeak | can't remember how far he got | 19:50 |
*** edmondsw has quit IRC | 19:53 | |
*** jmckind_ has joined #openstack-security | 19:53 | |
*** ninag has quit IRC | 19:54 | |
*** ninag has joined #openstack-security | 19:55 | |
*** jmckind has quit IRC | 19:55 | |
*** avarner has joined #openstack-security | 19:57 | |
*** ninag has quit IRC | 19:58 | |
*** rcernin has quit IRC | 19:58 | |
*** ninag has joined #openstack-security | 19:59 | |
*** ninag_ has joined #openstack-security | 20:01 | |
*** ninag_ has quit IRC | 20:02 | |
*** ninag_ has joined #openstack-security | 20:02 | |
*** ninag has quit IRC | 20:03 | |
*** jmckind has joined #openstack-security | 20:06 | |
*** jmckind_ has quit IRC | 20:09 | |
*** diazjf has quit IRC | 20:11 | |
*** jhfeng has quit IRC | 20:21 | |
*** jhfeng has joined #openstack-security | 20:29 | |
*** jhfeng has quit IRC | 20:30 | |
*** diazjf has joined #openstack-security | 20:31 | |
*** rcernin has joined #openstack-security | 20:32 | |
*** salv-orlando has joined #openstack-security | 20:47 | |
*** jhfeng has joined #openstack-security | 20:48 | |
*** zul has quit IRC | 20:52 | |
*** diazjf has quit IRC | 20:54 | |
*** bknudson has joined #openstack-security | 20:55 | |
*** salv-orlando has quit IRC | 21:00 | |
*** diazjf has joined #openstack-security | 21:06 | |
*** bpokorny_ has quit IRC | 21:26 | |
*** bpokorny has joined #openstack-security | 21:27 | |
*** rcernin has quit IRC | 21:28 | |
*** bpokorny has quit IRC | 21:28 | |
*** bpokorny has joined #openstack-security | 21:29 | |
*** salv-orlando has joined #openstack-security | 21:30 | |
*** avarner_ has joined #openstack-security | 21:30 | |
*** avarner has quit IRC | 21:34 | |
*** avarner_ has quit IRC | 21:38 | |
*** avarner has joined #openstack-security | 21:59 | |
*** salv-orl_ has joined #openstack-security | 22:06 | |
*** diazjf has quit IRC | 22:07 | |
*** salv-orlando has quit IRC | 22:09 | |
*** diazjf has joined #openstack-security | 22:10 | |
*** cjschaef has quit IRC | 22:44 | |
*** ninag_ has quit IRC | 22:48 | |
*** ninag has joined #openstack-security | 22:48 | |
*** ccneill has quit IRC | 22:50 | |
*** ninag has quit IRC | 22:52 | |
*** jhfeng has quit IRC | 23:06 | |
*** jmckind_ has joined #openstack-security | 23:10 | |
*** edtubill has quit IRC | 23:11 | |
*** jmckind has quit IRC | 23:13 | |
*** jmckind has joined #openstack-security | 23:16 | |
*** jmckind_ has quit IRC | 23:19 | |
*** avarner has quit IRC | 23:21 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/anchor: Updated from global requirements https://review.openstack.org/271636 | 23:21 |
*** diazjf has quit IRC | 23:22 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 23:28 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!