*** openstack has joined #openstack-security | 00:23 | |
*** dave-mccowan has joined #openstack-security | 00:57 | |
*** tmcpeak has quit IRC | 01:14 | |
*** tmcpeak has joined #openstack-security | 01:41 | |
*** tmcpeak has quit IRC | 02:01 | |
*** Fred_Li has quit IRC | 02:21 | |
*** dave-mccowan has quit IRC | 03:17 | |
*** yuanying has quit IRC | 03:20 | |
*** yuanying has joined #openstack-security | 04:07 | |
*** pdesai has joined #openstack-security | 04:58 | |
*** pdesai has quit IRC | 05:03 | |
*** liverpooler has quit IRC | 05:59 | |
*** tesseract has joined #openstack-security | 07:16 | |
*** tesseract is now known as Guest64967 | 07:17 | |
*** Guest64967 has quit IRC | 07:21 | |
*** browne has quit IRC | 07:27 | |
*** eric_lopez has quit IRC | 07:28 | |
*** elo has joined #openstack-security | 07:30 | |
*** tesseract- has joined #openstack-security | 07:35 | |
*** liverpooler has joined #openstack-security | 07:49 | |
*** y_sawai has joined #openstack-security | 08:10 | |
*** aurelien_ has joined #openstack-security | 08:13 | |
*** liverpooler has quit IRC | 08:14 | |
*** liverpooler has joined #openstack-security | 08:14 | |
*** aurelien_ has left #openstack-security | 08:15 | |
openstackgerrit | chen.xing proposed openstack/security-doc: [security-guide]Update the content of the signed image validation https://review.openstack.org/287640 | 08:33 |
---|---|---|
*** ig0r_ has quit IRC | 08:39 | |
*** salv-orlando has joined #openstack-security | 09:11 | |
*** openstackgerrit has quit IRC | 09:53 | |
*** openstackgerrit_ is now known as openstackgerrit | 09:53 | |
*** openstackgerrit has quit IRC | 09:53 | |
*** openstackgerrit_ has joined #openstack-security | 09:53 | |
*** openstackgerrit has joined #openstack-security | 09:54 | |
*** openstackgerrit_ is now known as openstackgerrit | 09:54 | |
*** openstackgerrit_ has joined #openstack-security | 09:55 | |
*** openstackgerrit has quit IRC | 09:55 | |
*** openstackgerrit has joined #openstack-security | 09:56 | |
*** ykotko has joined #openstack-security | 10:24 | |
ykotko | any updates ? https://bugs.launchpad.net/bandit/+bug/1554112 | 10:35 |
openstack | Launchpad bug 1554112 in Bandit "After excluding plugin from the bandit.yaml it still was used during the scaning" [Undecided,Confirmed] - Assigned to Eric Brown (ericwb) | 10:35 |
ykotko | and one more question do you have any description of plugins in bandit.yaml ? | 10:44 |
ykotko | ok. have found the description, but what about https://bugs.launchpad.net/bandit/+bug/1554112 | 10:56 |
openstack | Launchpad bug 1554112 in Bandit "After excluding plugin from the bandit.yaml it still was used during the scaning" [Undecided,Confirmed] - Assigned to Eric Brown (ericwb) | 10:56 |
ykotko | can somebody look at | 10:56 |
ykotko | ?? | 10:56 |
*** salv-orlando has quit IRC | 10:56 | |
*** openstackgerrit has quit IRC | 11:18 | |
*** openstackgerrit has joined #openstack-security | 11:18 | |
*** y_sawai has quit IRC | 11:37 | |
*** dave-mccowan has joined #openstack-security | 11:52 | |
*** salv-orlando has joined #openstack-security | 11:57 | |
*** salv-orlando has quit IRC | 12:28 | |
*** pcaruana has quit IRC | 12:28 | |
*** ninag has joined #openstack-security | 12:57 | |
ykotko | any updates ? https://bugs.launchpad.net/bandit/+bug/1554112 | 13:00 |
openstack | Launchpad bug 1554112 in Bandit "After excluding plugin from the bandit.yaml it still was used during the scaning" [Undecided,Confirmed] - Assigned to Eric Brown (ericwb) | 13:00 |
ykotko | @chair6 can you look at https://bugs.launchpad.net/bandit/+bug/1554112 | 13:02 |
openstack | Launchpad bug 1554112 in Bandit "After excluding plugin from the bandit.yaml it still was used during the scaning" [Undecided,Confirmed] - Assigned to Eric Brown (ericwb) | 13:02 |
*** rcernin has joined #openstack-security | 13:03 | |
ykotko | @tmcpeak: can you look at https://bugs.launchpad.net/bandit/+bug/1554112 | 13:11 |
openstack | Launchpad bug 1554112 in Bandit "After excluding plugin from the bandit.yaml it still was used during the scaning" [Undecided,Confirmed] - Assigned to Eric Brown (ericwb) | 13:11 |
*** kro_sinus_hell is now known as krot_sinus_purga | 13:15 | |
*** krot_sinus_purga is now known as kro_sniffles | 13:15 | |
*** Sokonesi has joined #openstack-security | 13:17 | |
*** Sokonesi has left #openstack-security | 13:19 | |
*** ig0r_ has joined #openstack-security | 13:24 | |
*** salv-orlando has joined #openstack-security | 13:29 | |
*** ninag has quit IRC | 13:34 | |
*** ninag has joined #openstack-security | 13:34 | |
*** d0ugal has quit IRC | 13:35 | |
*** d0ugal has joined #openstack-security | 13:35 | |
*** ninag_ has joined #openstack-security | 13:36 | |
ykotko | @tkelsey: can you look at https://bugs.launchpad.net/bandit/+bug/1554112 | 13:36 |
openstack | Launchpad bug 1554112 in Bandit "After excluding plugin from the bandit.yaml it still was used during the scaning" [Undecided,Confirmed] - Assigned to Eric Brown (ericwb) | 13:36 |
*** ninag has quit IRC | 13:39 | |
*** salv-orlando has quit IRC | 13:40 | |
*** edmondsw has joined #openstack-security | 13:41 | |
ykotko | @browne: can you look at https://bugs.launchpad.net/bandit/+bug/1554112 | 13:46 |
openstack | Launchpad bug 1554112 in Bandit "After excluding plugin from the bandit.yaml it still was used during the scaning" [Undecided,Confirmed] - Assigned to Eric Brown (ericwb) | 13:46 |
*** cleong has joined #openstack-security | 13:53 | |
*** edtubill has joined #openstack-security | 14:02 | |
*** avarner__ has joined #openstack-security | 14:02 | |
ykotko | @browne: can you look at https://bugs.launchpad.net/bandit/+bug/1554112 | 14:02 |
openstack | Launchpad bug 1554112 in Bandit "After excluding plugin from the bandit.yaml it still was used during the scaning" [Undecided,Confirmed] - Assigned to Eric Brown (ericwb) | 14:03 |
*** sigmavirus24_awa is now known as sigmavirus24 | 14:06 | |
*** salv-orlando has joined #openstack-security | 14:15 | |
*** tmcpeak has joined #openstack-security | 14:42 | |
*** ninag_ has quit IRC | 14:55 | |
*** ninag has joined #openstack-security | 14:55 | |
*** ninag has quit IRC | 14:59 | |
*** jhfeng has joined #openstack-security | 15:10 | |
*** edtubill has quit IRC | 15:13 | |
*** liverpooler has quit IRC | 15:17 | |
*** browne has joined #openstack-security | 15:29 | |
*** ninag has joined #openstack-security | 15:31 | |
*** bpokorny has joined #openstack-security | 15:42 | |
*** austin987 has quit IRC | 15:50 | |
*** browne has quit IRC | 15:51 | |
*** pdesai has joined #openstack-security | 16:00 | |
*** avarner__ has quit IRC | 16:23 | |
*** avarner has joined #openstack-security | 16:27 | |
*** avarner_ has joined #openstack-security | 16:28 | |
*** avarner has quit IRC | 16:32 | |
*** browne has joined #openstack-security | 16:38 | |
chair6 | hey @ykotko, i took another look at your bug and it looks like our docs haven't kept up very well with recent changes around bandit config/profiles | 16:46 |
chair6 | what are you actually trying to do? run bandit against openstack/fuel-web.git but exclude a few specific tests? | 16:47 |
*** pdesai has quit IRC | 16:53 | |
chair6 | in that case, you should just be able to drop a .bandit file in fuel-web and point bandit at it.. i'll drop a comment on the bug | 16:58 |
*** sigmavirus24 is now known as sigmavirus24_awa | 17:02 | |
*** jass93 has joined #openstack-security | 17:02 | |
*** avarner_ has quit IRC | 17:16 | |
openstackgerrit | Michael Dong proposed openstack/syntribos: added Solum payloads https://review.openstack.org/292477 | 17:16 |
ykotko | @chair6: I am trying to generate bandit.yaml with necessary excludes | 17:17 |
ykotko | then use it for scaning | 17:17 |
ykotko | but the tests from excludes using as well | 17:18 |
ykotko | and if use -p parameter got the traceback | 17:20 |
ykotko | see the description | 17:21 |
ykotko | I can reproduce it again | 17:21 |
*** avarner has joined #openstack-security | 17:22 | |
chair6 | yeah, i repro'd too | 17:23 |
chair6 | seems our docs and code don't line up, due to recent config/profile changes | 17:24 |
chair6 | i'll have to sync up with the bandit team on where we're at | 17:25 |
tmcpeak | chair6: which bug? | 17:25 |
*** tkelsey has joined #openstack-security | 17:26 | |
ykotko | <ykotko> @tmcpeak: can you look at https://bugs.launchpad.net/bandit/+bug/1554112 | 17:27 |
openstack | Launchpad bug 1554112 in Bandit "After excluding plugin from the bandit.yaml it still was used during the scaning" [Undecided,Confirmed] - Assigned to Eric Brown (ericwb) | 17:27 |
tkelsey | browne: hey man, you about? | 17:27 |
browne | yep, what's up | 17:27 |
tkelsey | just wanted to sync up on https://review.openstack.org/#/c/281560/ | 17:27 |
tkelsey | whats the deal here? | 17:27 |
tmcpeak | ykotko: did you intend to use the profile? | 17:28 |
tmcpeak | oh nevermind | 17:28 |
tmcpeak | actually reading | 17:28 |
browne | tkelsey: so the remaining issue is a problem in blacklist import where the importing of Crypto did not raise an issue before, but now it is | 17:29 |
tkelsey | oh i see | 17:29 |
browne | and we apparently had no functional tests for it. | 17:29 |
browne | so, i was wondering whether we should drop Crypto from the blacklist import since i'm not even sure why we raise an issue on it | 17:29 |
tkelsey | yeah, Let me have a check and see, but that sounds like the right more | 17:30 |
tkelsey | *move | 17:30 |
tkelsey | "Consider possible security implications associated with these modules" ... so its just an FYI, lets drop it | 17:32 |
tkelsey | i think there are explicit checks for band cypher modes and the like | 17:33 |
tkelsey | yeah there are, that should be sufficient. I'll make a patch to drop the FYI | 17:33 |
tmcpeak | ykotko: if you exclude by ID (B110) does it work? | 17:34 |
tkelsey | tmcpeak: anything I can help with? | 17:34 |
browne | tkelsey: cool, i'll put up a patch | 17:36 |
tmcpeak | tkelsey: we're looking at this: https://bugs.launchpad.net/bandit/+bug/1554112 | 17:36 |
openstack | Launchpad bug 1554112 in Bandit "After excluding plugin from the bandit.yaml it still was used during the scaning" [Undecided,Confirmed] - Assigned to Eric Brown (ericwb) | 17:36 |
tmcpeak | also it looks like our config generator isn't exporting section titles anymore | 17:36 |
tkelsey | browne: im just about to :) | 17:36 |
tmcpeak | for include and exclude | 17:36 |
browne | tkelsey: ok, cool, go for it | 17:37 |
ykotko | bandit -c bandit_conf.yaml -r "</path/>" -n5 -p <profile_name> | 17:37 |
ykotko | gave the trace | 17:39 |
tmcpeak | ok we've definitely got a bug | 17:39 |
tmcpeak | a few if you include the documentation sucks | 17:39 |
tkelsey | tmcpeak: yeah it needs fixing for the new bandit stuff :( | 17:40 |
tkelsey | ykotko: thanks for reporting the issue, we will look to fix it | 17:40 |
tmcpeak | ykotko: yeah good catch | 17:40 |
tmcpeak | thank you | 17:40 |
ykotko | :) | 17:41 |
*** ninag has quit IRC | 17:42 | |
*** ninag has joined #openstack-security | 17:43 | |
*** ninag has quit IRC | 17:47 | |
openstackgerrit | Tim Kelsey proposed openstack/bandit: Trimming Blacklists https://review.openstack.org/293617 | 17:49 |
tkelsey | browne: ^ | 17:49 |
browne | oh so we did have tests on it. strange it doesn't fail in 0.17.3, but does in our master | 17:50 |
tkelsey | yeah its odd, do you want to try mixing your patch on top of that and seeing if it passes | 17:52 |
*** rcernin has quit IRC | 17:53 | |
browne | i'll try rebasing on your patch to make sure the integrations clear up | 17:54 |
*** salv-orl_ has joined #openstack-security | 17:54 | |
tkelsey | browne: good plan, also yeah lol I'll fix the commit message | 17:55 |
*** salv-orlando has quit IRC | 17:56 | |
openstackgerrit | Tim Kelsey proposed openstack/bandit: Trimming Blacklists https://review.openstack.org/293617 | 17:56 |
*** browne has quit IRC | 17:59 | |
openstackgerrit | Tim Kelsey proposed openstack/bandit: Blacklists now check node types are valid https://review.openstack.org/281365 | 18:01 |
*** browne has joined #openstack-security | 18:02 | |
openstackgerrit | Tim Kelsey proposed openstack/bandit: Blacklists now check node types are valid https://review.openstack.org/281365 | 18:03 |
*** ninag has joined #openstack-security | 18:03 | |
*** pdesai has joined #openstack-security | 18:03 | |
*** ninag has quit IRC | 18:04 | |
*** ninag has joined #openstack-security | 18:05 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 18:07 | |
*** ninag has quit IRC | 18:09 | |
openstackgerrit | Eric Brown proposed openstack/bandit: Ensure error exit codes fail integrations https://review.openstack.org/281560 | 18:14 |
*** tesseract- has quit IRC | 18:19 | |
*** ninag has joined #openstack-security | 18:25 | |
*** ninag has quit IRC | 18:33 | |
*** ninag has joined #openstack-security | 18:33 | |
*** ninag has quit IRC | 18:34 | |
browne | tkelsey: ok, all integrations pass excpet oslo.messaging. and that's because there's a patch for that currently waiting +2 and merge | 18:34 |
*** ninag has joined #openstack-security | 18:34 | |
tkelsey | browne: got a link? | 18:40 |
*** ninag has quit IRC | 18:40 | |
browne | https://review.openstack.org/#/c/286506/ | 18:40 |
openstackgerrit | Jamie Finnigan proposed openstack/bandit: Fix typos in CLI output https://review.openstack.org/293645 | 18:45 |
chair6 | ^ uggh, now i'm the typo nit fixer.. but that one was triggering my ocd :) | 18:47 |
tmcpeak | chair6: why, you don't like exculde? | 18:51 |
tmcpeak | it's spanish for something I'm sure | 18:52 |
tmcpeak | it means "exclude the" in Romanian ;) | 18:52 |
*** amit2131 has quit IRC | 18:55 | |
*** amit213 has joined #openstack-security | 18:55 | |
chair6 | hah | 18:57 |
openstackgerrit | Merged openstack/bandit: Fix typos in CLI output https://review.openstack.org/293645 | 19:13 |
openstackgerrit | Merged openstack/bandit: Pass environment variables of proxy to tox https://review.openstack.org/286177 | 19:13 |
*** salv-orl_ has quit IRC | 19:15 | |
*** ninag has joined #openstack-security | 19:15 | |
*** browne has quit IRC | 19:19 | |
*** ninag has quit IRC | 19:19 | |
*** browne has joined #openstack-security | 19:22 | |
*** kro_sniffles is now known as kro_mnckn_doc | 19:27 | |
*** ninag has joined #openstack-security | 19:36 | |
*** browne has quit IRC | 19:42 | |
*** ig0r_ has quit IRC | 19:55 | |
*** salv-orlando has joined #openstack-security | 20:01 | |
*** bpokorny_ has joined #openstack-security | 20:12 | |
*** bpokorny has quit IRC | 20:13 | |
*** bpokorny_ has quit IRC | 20:15 | |
*** bpokorny has joined #openstack-security | 20:15 | |
*** avarner has quit IRC | 20:20 | |
*** bpokorny has quit IRC | 20:20 | |
*** bpokorny has joined #openstack-security | 20:20 | |
*** avarner has joined #openstack-security | 20:23 | |
*** cleong has quit IRC | 20:50 | |
*** ninag has quit IRC | 21:00 | |
*** bpokorny has quit IRC | 21:03 | |
*** bpokorny has joined #openstack-security | 21:03 | |
*** mvaldes has joined #openstack-security | 21:09 | |
*** browne has joined #openstack-security | 21:16 | |
*** kro_mnckn_doc has quit IRC | 21:19 | |
*** tkelsey has quit IRC | 21:41 | |
openstackgerrit | Merged openstack/bandit: Trimming Blacklists https://review.openstack.org/293617 | 21:48 |
*** sigmavirus24 is now known as sigmavirus24_awa | 21:48 | |
*** pdesai has quit IRC | 21:56 | |
*** jass93_ has joined #openstack-security | 22:02 | |
*** jass93 has quit IRC | 22:03 | |
openstackgerrit | Merged openstack/syntribos: added Solum payloads https://review.openstack.org/292477 | 22:19 |
*** mvaldes has quit IRC | 22:28 | |
*** edmondsw has quit IRC | 22:43 | |
*** karlamrhein has joined #openstack-security | 23:02 | |
*** krotscheck has joined #openstack-security | 23:11 | |
openstackgerrit | Eric Brown proposed openstack/bandit: Update command line help baseline report https://review.openstack.org/289553 | 23:11 |
*** karlamrhein has quit IRC | 23:25 | |
*** jhfeng has quit IRC | 23:39 | |
*** salv-orl_ has joined #openstack-security | 23:54 | |
*** salv-orlando has quit IRC | 23:57 | |
*** austin987 has joined #openstack-security | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!