*** tmcpeak has quit IRC | 00:04 | |
*** austin987 has quit IRC | 00:16 | |
*** tmcpeak has joined #openstack-security | 00:24 | |
*** austin987 has joined #openstack-security | 00:31 | |
*** tmcpeak has quit IRC | 00:37 | |
*** tmcpeak has joined #openstack-security | 00:38 | |
*** salv-orl_ has quit IRC | 00:40 | |
*** JAHoagie has joined #openstack-security | 00:49 | |
*** JAHoagie has quit IRC | 01:00 | |
*** bpokorny has quit IRC | 01:04 | |
*** tmcpeak has quit IRC | 01:08 | |
*** browne has quit IRC | 02:03 | |
*** salv-orlando has joined #openstack-security | 02:03 | |
*** jhfeng has joined #openstack-security | 02:08 | |
*** salv-orlando has quit IRC | 02:12 | |
*** avarner has quit IRC | 02:12 | |
*** jhfeng has quit IRC | 02:19 | |
*** dave-mccowan has quit IRC | 02:19 | |
*** nkinder has quit IRC | 02:19 | |
*** jraim has quit IRC | 02:19 | |
*** jhfeng has joined #openstack-security | 02:25 | |
*** dave-mccowan has joined #openstack-security | 02:25 | |
*** nkinder has joined #openstack-security | 02:25 | |
*** jraim has joined #openstack-security | 02:25 | |
*** tkelsey has joined #openstack-security | 02:50 | |
*** tkelsey has quit IRC | 02:54 | |
*** markvoelker has quit IRC | 03:15 | |
*** salv-orlando has joined #openstack-security | 03:17 | |
*** salv-orlando has quit IRC | 03:26 | |
*** tmcpeak has joined #openstack-security | 03:44 | |
*** tmcpeak has quit IRC | 03:49 | |
*** jhfeng has quit IRC | 03:59 | |
*** dave-mccowan has quit IRC | 04:00 | |
*** jass93 has joined #openstack-security | 04:01 | |
*** jass93_ has quit IRC | 04:02 | |
*** tmcpeak has joined #openstack-security | 04:05 | |
*** tmcpeak has quit IRC | 04:09 | |
*** tmcpeak has joined #openstack-security | 04:26 | |
*** tmcpeak has quit IRC | 04:30 | |
*** browne has joined #openstack-security | 04:39 | |
*** salv-orlando has joined #openstack-security | 04:48 | |
*** austin987 has quit IRC | 04:50 | |
*** salv-orlando has quit IRC | 04:51 | |
*** markvoelker has joined #openstack-security | 05:15 | |
*** markvoelker has quit IRC | 05:21 | |
*** tmcpeak has joined #openstack-security | 05:23 | |
*** tmcpeak has quit IRC | 05:27 | |
*** salv-orlando has joined #openstack-security | 06:13 | |
*** tmcpeak has joined #openstack-security | 06:20 | |
*** salv-orlando has quit IRC | 06:23 | |
*** tmcpeak has quit IRC | 06:24 | |
*** BigWillie has joined #openstack-security | 06:33 | |
*** BigWillie has quit IRC | 06:34 | |
*** tmcpeak has joined #openstack-security | 06:40 | |
*** tmcpeak has quit IRC | 06:44 | |
*** tkelsey has joined #openstack-security | 06:51 | |
*** markvoelker has joined #openstack-security | 06:52 | |
*** tkelsey has quit IRC | 06:56 | |
*** markvoelker has quit IRC | 06:58 | |
*** tesseract has joined #openstack-security | 07:15 | |
*** tesseract is now known as Guest57182 | 07:15 | |
*** shakamunyi has quit IRC | 07:18 | |
*** shakamunyi has joined #openstack-security | 07:23 | |
*** salv-orlando has joined #openstack-security | 07:32 | |
*** rcernin has joined #openstack-security | 07:39 | |
*** salv-orlando has quit IRC | 07:40 | |
*** tkelsey has joined #openstack-security | 07:43 | |
*** y_sawai has joined #openstack-security | 07:46 | |
*** tkelsey has quit IRC | 07:57 | |
*** browne has quit IRC | 08:02 | |
*** salv-orlando has joined #openstack-security | 08:23 | |
*** pcaruana has joined #openstack-security | 08:24 | |
*** barra204 has joined #openstack-security | 08:43 | |
*** shakamunyi has quit IRC | 08:44 | |
*** liverpooler has joined #openstack-security | 08:49 | |
*** y_sawai has quit IRC | 08:57 | |
*** y_sawai has joined #openstack-security | 09:01 | |
*** salv-orlando has quit IRC | 09:07 | |
*** d0ugal has quit IRC | 09:13 | |
*** d0ugal has joined #openstack-security | 09:15 | |
*** y_sawai has quit IRC | 09:33 | |
*** y_sawai has joined #openstack-security | 09:33 | |
*** y_sawai has quit IRC | 09:33 | |
*** y_sawai has joined #openstack-security | 09:40 | |
*** tkelsey has joined #openstack-security | 09:54 | |
*** tkelsey has quit IRC | 09:58 | |
*** y_sawai has quit IRC | 10:04 | |
*** y_sawai has joined #openstack-security | 10:07 | |
*** y_sawai has quit IRC | 10:35 | |
*** tkelsey has joined #openstack-security | 10:42 | |
*** tkelsey has quit IRC | 10:46 | |
*** salv-orlando has joined #openstack-security | 11:07 | |
*** salv-orlando has quit IRC | 11:18 | |
*** openstackgerrit has quit IRC | 11:48 | |
*** openstackgerrit has joined #openstack-security | 11:48 | |
*** dave-mccowan has joined #openstack-security | 11:53 | |
*** edmondsw has joined #openstack-security | 12:18 | |
*** tkelsey has joined #openstack-security | 12:43 | |
*** ninag has joined #openstack-security | 12:43 | |
*** tkelsey has quit IRC | 12:47 | |
*** salv-orlando has joined #openstack-security | 12:48 | |
*** Trident has quit IRC | 12:57 | |
*** salv-orlando has quit IRC | 12:58 | |
*** markvoelker has joined #openstack-security | 13:11 | |
*** Trident has joined #openstack-security | 13:12 | |
*** salv-orlando has joined #openstack-security | 13:15 | |
*** avarner has joined #openstack-security | 13:44 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 13:47 | |
*** cleong has joined #openstack-security | 13:52 | |
*** mvaldes has joined #openstack-security | 14:00 | |
*** mvaldes1 has joined #openstack-security | 14:06 | |
*** mvaldes has quit IRC | 14:10 | |
*** cjschaef has joined #openstack-security | 14:20 | |
*** pcaruana has quit IRC | 14:28 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 14:40 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 14:41 | |
*** ccneill has joined #openstack-security | 14:45 | |
*** cjschaef has quit IRC | 14:49 | |
*** ccneill_ has joined #openstack-security | 14:52 | |
*** edtubill has joined #openstack-security | 14:53 | |
*** ccneill has quit IRC | 14:54 | |
*** ccneill_ has quit IRC | 14:57 | |
*** cjschaef has joined #openstack-security | 14:59 | |
*** alejandrito has joined #openstack-security | 15:05 | |
*** tmcpeak has joined #openstack-security | 15:11 | |
*** jhfeng has joined #openstack-security | 15:16 | |
*** browne has joined #openstack-security | 15:22 | |
*** liverpooler has quit IRC | 15:23 | |
*** tkelsey has joined #openstack-security | 15:25 | |
*** avarner has quit IRC | 15:33 | |
*** jhfeng has quit IRC | 15:39 | |
*** pdesai has joined #openstack-security | 15:40 | |
*** pdesai has quit IRC | 15:44 | |
*** pdesai has joined #openstack-security | 15:45 | |
*** JAHoagie has joined #openstack-security | 15:47 | |
*** pdesai1 has joined #openstack-security | 15:48 | |
*** pdesai has quit IRC | 15:49 | |
*** bpokorny has joined #openstack-security | 15:50 | |
*** pdesai has joined #openstack-security | 15:52 | |
*** pdesai1 has quit IRC | 15:53 | |
*** pdesai1 has joined #openstack-security | 15:56 | |
*** pdesai has quit IRC | 15:57 | |
openstackgerrit | Joel Coffman proposed openstack/security-doc: [security-guide]Update the content of the signed image validation https://review.openstack.org/287640 | 15:57 |
---|---|---|
tkelsey | hi ykotko, are you about? | 16:00 |
tmcpeak | daylight savings? | 16:00 |
tkelsey | tmcpeak: humm? | 16:01 |
tmcpeak | thought it was meeting time | 16:01 |
tmcpeak | daylight savings in the US always messes me up | 16:01 |
tkelsey | bah, forgot about that | 16:01 |
tkelsey | no its in an hour | 16:02 |
tmcpeak | this is the one people in US show up early for | 16:02 |
tmcpeak | one in September people miss ;) | 16:02 |
tkelsey | lol | 16:02 |
tkelsey | so tmcpeak were you able to repro https://bugs.launchpad.net/bandit/+bug/1554112 ? | 16:03 |
openstack | Launchpad bug 1554112 in Bandit "After excluding plugin from the bandit.yaml it still was used during the scaning" [Critical,Confirmed] - Assigned to Tim Kelsey (tim-kelsey) | 16:03 |
tmcpeak | yeah not only that but check this out | 16:03 |
tmcpeak | one sec | 16:03 |
tmcpeak | tkelsey: run this bandit -r <project> -s B110 and look carefully at the headers | 16:04 |
tmcpeak | command line exclude is being included in profile exclude list | 16:04 |
tkelsey | oh yeah | 16:05 |
tkelsey | d'oh my bad, I'll fix that one. I was just trying to repro the other one | 16:05 |
tkelsey | is there a bug in LP for the header one? | 16:06 |
tkelsey | if not i'll make one | 16:06 |
tmcpeak | tkelsey: and also config generator just puts this: # (optional) list included tests here: | 16:06 |
tmcpeak | it should aslo put the option (with comment) that you'd actually use to exclude/include tests | 16:07 |
tmcpeak | tkelsey: no, I don't have a bug | 16:08 |
tmcpeak | but yeah, I also repro'd that issue | 16:08 |
tkelsey | ok, let me fix that simple one first :P then I'll talk about repro for the second, I didnt manage to trigger it | 16:10 |
tmcpeak | ok | 16:13 |
*** avarner has joined #openstack-security | 16:14 | |
*** pdesai has joined #openstack-security | 16:20 | |
openstackgerrit | Tim Kelsey proposed openstack/bandit: The source of include/exclude conditions was incorrectly reported https://review.openstack.org/294135 | 16:21 |
*** sicarie has joined #openstack-security | 16:22 | |
*** pcaruana has joined #openstack-security | 16:22 | |
tkelsey | tmcpeak: ^ | 16:22 |
*** pdesai1 has quit IRC | 16:22 | |
*** cjschaef has quit IRC | 16:25 | |
*** salv-orlando has quit IRC | 16:25 | |
tmcpeak | tkelsey: looking | 16:25 |
tkelsey | ty | 16:25 |
*** salv-orlando has joined #openstack-security | 16:26 | |
*** cjschaef has joined #openstack-security | 16:27 | |
*** browne has quit IRC | 16:29 | |
*** ninag has quit IRC | 16:29 | |
*** ninag has joined #openstack-security | 16:29 | |
*** ninag_ has joined #openstack-security | 16:30 | |
*** ninag_ has quit IRC | 16:32 | |
tkelsey | cool, so tmcpeak how did you repro that other bug then? I tried using the config on LP and the All profile but it seemed to work for me? | 16:32 |
*** ninag_ has joined #openstack-security | 16:33 | |
tmcpeak | yeah there was another one yesterday | 16:33 |
tmcpeak | let me see if I have it in my scrollback | 16:34 |
*** avarner_ has joined #openstack-security | 16:34 | |
*** ninag has quit IRC | 16:34 | |
tmcpeak | tkelsey: I don't have his (her) paste anymore | 16:36 |
*** avarner__ has joined #openstack-security | 16:36 | |
*** avarner_ has quit IRC | 16:36 | |
tkelsey | ok, I'll do some digging, thanks man | 16:37 |
tmcpeak | the config didn't look right though | 16:38 |
*** avarner has quit IRC | 16:38 | |
tmcpeak | I remember that :) | 16:38 |
tmcpeak | seemed like the case where we should have better validation of the things in the config file | 16:38 |
tmcpeak | it dumped a traceback | 16:38 |
tkelsey | yeah, the config needs validating for sure | 16:39 |
*** ninag_ has quit IRC | 16:44 | |
*** ninag has joined #openstack-security | 16:44 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 16:45 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 16:45 | |
*** yarkot_ has joined #openstack-security | 16:48 | |
*** alejandrito has quit IRC | 16:49 | |
*** ninag has quit IRC | 16:49 | |
*** alejandrito has joined #openstack-security | 16:51 | |
*** singlethink has joined #openstack-security | 16:59 | |
*** hyakuhei has joined #openstack-security | 17:01 | |
*** alejandrito has quit IRC | 17:01 | |
*** ninag has joined #openstack-security | 17:08 | |
*** browne has joined #openstack-security | 17:15 | |
*** B_Smith_ has quit IRC | 17:15 | |
*** B_Smith has joined #openstack-security | 17:16 | |
*** yarkot_ has quit IRC | 17:19 | |
sigmavirus24 | I have to cut out of the meeting early tmcpeak but I'll chat with y'all later | 17:28 |
tmcpeak | sigmavirus24: sounds good | 17:29 |
openstackgerrit | Merged openstack/bandit: The source of include/exclude conditions was incorrectly reported https://review.openstack.org/294135 | 17:31 |
*** ninag has quit IRC | 17:34 | |
*** ninag has joined #openstack-security | 17:35 | |
*** ninag has quit IRC | 17:36 | |
*** ninag has joined #openstack-security | 17:36 | |
*** Guest57182 has quit IRC | 17:36 | |
*** ninag has quit IRC | 17:39 | |
*** ninag has joined #openstack-security | 17:39 | |
*** ninag has quit IRC | 17:43 | |
openstackgerrit | Merged openstack/bandit: Update command line help baseline report https://review.openstack.org/289553 | 17:53 |
*** rcernin has quit IRC | 17:55 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 18:00 | |
*** hyakuhei has quit IRC | 18:00 | |
*** sicarie has quit IRC | 18:00 | |
*** singlethink has quit IRC | 18:03 | |
*** ninag has joined #openstack-security | 18:17 | |
*** pcaruana has quit IRC | 18:18 | |
*** cleong has quit IRC | 18:22 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 18:28 | |
*** pcaruana has joined #openstack-security | 18:30 | |
tkelsey | tmcpeak: I cant seem to repro this bug | 18:42 |
tkelsey | ykotko: are you about? | 18:43 |
tmcpeak | tkelsey: hmm | 18:43 |
tmcpeak | tkelsey: maybe drop a comment on the bug? | 18:44 |
tmcpeak | ask ykotko to attach pastebin of his profile and the command line | 18:44 |
tkelsey | so im running "bandit -c ./bandit_hack.yml -r ./fuel-web/ -n5 -p All" with my config edited to match the one in the bug report | 18:44 |
tmcpeak | then go do something fun with the evening :) | 18:44 |
tmcpeak | yeah I didn't repro with the one in the bug report either | 18:44 |
tkelsey | heh, yeah I want to try and get this one nailed down if i can | 18:45 |
tmcpeak | he put a new one which I promptly lost | 18:45 |
tkelsey | ah lol | 18:45 |
tmcpeak | he/she | 18:45 |
tkelsey | humm, OK, well i cant repro it, so i'll comment and se if i can get some more info | 18:46 |
tmcpeak | cool | 18:47 |
chair6 | if this is the same bug, i repro'd it yesterday.. but from current bandit release on pypi | 18:48 |
tmcpeak | ahh ok | 18:52 |
tmcpeak | I repro'd with a different config on master | 18:52 |
*** ninag has quit IRC | 18:56 | |
*** ninag has joined #openstack-security | 19:00 | |
*** ninag has quit IRC | 19:05 | |
*** tkelsey has quit IRC | 19:08 | |
*** ninag has joined #openstack-security | 19:10 | |
*** mvaldes1 has quit IRC | 19:12 | |
*** tkelsey has joined #openstack-security | 19:12 | |
*** salv-orl_ has joined #openstack-security | 19:16 | |
*** salv-orlando has quit IRC | 19:19 | |
openstackgerrit | Merged openstack/security-doc: add a readme to the security guide project https://review.openstack.org/286152 | 19:20 |
*** mvaldes has joined #openstack-security | 19:23 | |
*** ninag has quit IRC | 19:43 | |
*** tkelsey has quit IRC | 19:49 | |
*** avarner_ has joined #openstack-security | 19:59 | |
*** avarner__ has quit IRC | 20:02 | |
*** pcaruana has quit IRC | 20:17 | |
*** pcaruana has joined #openstack-security | 20:30 | |
*** ninag has joined #openstack-security | 20:34 | |
*** ametts has joined #openstack-security | 20:42 | |
*** mvaldes has quit IRC | 20:56 | |
*** mvaldes has joined #openstack-security | 21:06 | |
*** pdesai has quit IRC | 21:30 | |
*** cjschaef has quit IRC | 21:33 | |
*** tmcpeak has quit IRC | 21:35 | |
*** tmcpeak has joined #openstack-security | 21:36 | |
*** mvaldes has quit IRC | 21:43 | |
*** ninag has quit IRC | 21:44 | |
*** jass93_ has joined #openstack-security | 22:02 | |
*** jass93 has quit IRC | 22:02 | |
*** nkinder has quit IRC | 22:04 | |
*** nkinder has joined #openstack-security | 22:04 | |
*** zul has joined #openstack-security | 22:06 | |
*** edtubill has quit IRC | 22:08 | |
*** ametts has quit IRC | 22:14 | |
*** zul has quit IRC | 22:18 | |
openstackgerrit | Eric Brown proposed openstack/bandit: Adding test for os.path.join with variables https://review.openstack.org/281441 | 22:21 |
*** bpokorny_ has joined #openstack-security | 22:31 | |
*** bpokorny has quit IRC | 22:34 | |
*** edtubill has joined #openstack-security | 22:40 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 22:40 | |
openstackgerrit | Merged openstack/security-doc: [security-guide]Update the content of the signed image validation https://review.openstack.org/287640 | 22:46 |
*** edtubill has quit IRC | 23:24 | |
*** bpokorny_ has quit IRC | 23:31 | |
*** bpokorny has joined #openstack-security | 23:32 | |
*** bpokorny has quit IRC | 23:32 | |
*** bpokorny has joined #openstack-security | 23:33 | |
*** Trident has quit IRC | 23:40 | |
*** Trident has joined #openstack-security | 23:40 | |
*** tmcpeak has quit IRC | 23:43 | |
*** markvoelker has quit IRC | 23:54 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!