*** yuanying has quit IRC | 00:08 | |
*** yuanying has joined #openstack-security | 01:04 | |
*** liujiong has joined #openstack-security | 01:29 | |
*** murphy_zhao has joined #openstack-security | 02:13 | |
*** catintheroof has quit IRC | 02:28 | |
*** catintheroof has joined #openstack-security | 02:30 | |
*** catintheroof has quit IRC | 02:34 | |
*** gouthamr has joined #openstack-security | 02:56 | |
*** yuanying_ has joined #openstack-security | 02:57 | |
*** yuanying has quit IRC | 03:00 | |
*** ediardo has quit IRC | 03:09 | |
*** liujiong_66 has joined #openstack-security | 03:09 | |
*** liujiong has quit IRC | 03:10 | |
*** gouthamr has quit IRC | 03:11 | |
*** ediardo has joined #openstack-security | 03:11 | |
*** yuanying_ has quit IRC | 03:13 | |
*** yuanying has joined #openstack-security | 03:13 | |
*** yuanying has quit IRC | 03:17 | |
*** nkinder has quit IRC | 03:50 | |
*** ashcrack4 has joined #openstack-security | 05:32 | |
*** ashcrack4 has quit IRC | 05:42 | |
openstackgerrit | Eric Brown proposed openstack/bandit: Add functional tests for B308, B321, and B402 https://review.openstack.org/412295 | 06:12 |
---|---|---|
*** yuanying has joined #openstack-security | 06:14 | |
*** yuanying has quit IRC | 06:19 | |
openstackgerrit | Eric Brown proposed openstack/bandit: Typo in calls doc for input call https://review.openstack.org/412306 | 06:32 |
*** liujiong_66 is now known as liujiong | 06:53 | |
openstackgerrit | Eric Brown proposed openstack/bandit: Handle curve keyword arg weak_cryptographic_key https://review.openstack.org/412316 | 07:02 |
openstackgerrit | Eric Brown proposed openstack/bandit: Handle curve keyword arg weak_cryptographic_key https://review.openstack.org/412316 | 07:03 |
*** tesseract has joined #openstack-security | 07:04 | |
*** tesseract is now known as Guest33254 | 07:05 | |
*** pcaruana has joined #openstack-security | 07:33 | |
openstackgerrit | Eric Brown proposed openstack/bandit: Handle several truth values for shell in subprocess https://review.openstack.org/412343 | 08:07 |
*** shohel has joined #openstack-security | 10:14 | |
*** yuanying has joined #openstack-security | 10:15 | |
*** shohel has quit IRC | 10:20 | |
*** shohel has joined #openstack-security | 10:20 | |
*** liujiong has quit IRC | 10:22 | |
*** shohel has quit IRC | 10:23 | |
*** shohel has joined #openstack-security | 10:25 | |
*** Serlex has joined #openstack-security | 10:32 | |
*** shohel has quit IRC | 10:39 | |
*** shohel has joined #openstack-security | 11:01 | |
*** dave-mccowan has joined #openstack-security | 11:26 | |
*** dave-mcc_ has joined #openstack-security | 11:45 | |
*** dave-mccowan has quit IRC | 11:48 | |
*** ChubbyBreakfast has joined #openstack-security | 12:02 | |
*** ChubbyBreakfast has left #openstack-security | 12:03 | |
*** catintheroof has joined #openstack-security | 12:18 | |
*** dave-mcc_ has quit IRC | 12:18 | |
*** lamt has quit IRC | 13:12 | |
*** gouthamr has joined #openstack-security | 13:26 | |
*** tiger_huyuan has joined #openstack-security | 13:30 | |
*** knangia has joined #openstack-security | 13:35 | |
*** tiger_huyuan has quit IRC | 13:39 | |
*** dwyde has joined #openstack-security | 13:40 | |
*** lamt has joined #openstack-security | 14:11 | |
*** cleong has joined #openstack-security | 14:14 | |
*** jmckind has joined #openstack-security | 14:39 | |
*** singlethink has joined #openstack-security | 14:44 | |
*** liverpooler has joined #openstack-security | 14:44 | |
*** liverpooler has quit IRC | 14:49 | |
*** liverpooler has joined #openstack-security | 14:51 | |
*** jmckind_ has joined #openstack-security | 14:52 | |
*** jmckind has quit IRC | 14:54 | |
*** jamielennox is now known as jamielennox|away | 14:56 | |
*** jmckind has joined #openstack-security | 15:09 | |
*** jmckind_ has quit IRC | 15:11 | |
*** liverpooler has quit IRC | 15:15 | |
*** liverpooler has joined #openstack-security | 15:15 | |
*** jmckind_ has joined #openstack-security | 15:16 | |
*** jmckind has quit IRC | 15:17 | |
*** jmckind__ has joined #openstack-security | 15:23 | |
*** jmckind_ has quit IRC | 15:23 | |
*** jmckind__ has quit IRC | 15:27 | |
*** jmckind has joined #openstack-security | 15:36 | |
*** shohel has quit IRC | 15:40 | |
*** Guest33254 has quit IRC | 16:02 | |
*** ccneill has joined #openstack-security | 16:03 | |
*** hongbin has joined #openstack-security | 16:10 | |
*** knangia has quit IRC | 16:10 | |
*** mhayden has quit IRC | 16:13 | |
*** pcaruana has quit IRC | 16:15 | |
*** diazjf has joined #openstack-security | 16:15 | |
*** browne has joined #openstack-security | 16:24 | |
*** ashcrack4 has joined #openstack-security | 16:32 | |
*** Serlex has quit IRC | 16:34 | |
*** jmckind has quit IRC | 16:36 | |
*** mhayden has joined #openstack-security | 16:41 | |
openstackgerrit | Travis McPeak proposed openstack/bandit: Update shell_injection_plugin to use whitelist https://review.openstack.org/412524 | 16:44 |
*** tmcpeak has joined #openstack-security | 17:08 | |
*** ashcrack4 has quit IRC | 17:08 | |
tmcpeak | browne: sigmavirus you guys around? | 17:08 |
sigmavirus | I am | 17:08 |
browne | yep | 17:08 |
tmcpeak | sweet | 17:09 |
tmcpeak | we've each got some work in flight to fix bugs | 17:09 |
tmcpeak | you guys around this week? | 17:09 |
tmcpeak | let's synch closely with eachother to push through the bug fixes? | 17:09 |
browne | yep, i'll be around | 17:09 |
tmcpeak | awesome | 17:09 |
sigmavirus | I'm out Friday, otherwise, ping me with priority reviews :) | 17:10 |
tmcpeak | I'm going to be fixing a few too | 17:10 |
tmcpeak | sigmavirus: ack, thank you | 17:10 |
tmcpeak | I thought you had some in flight too | 17:10 |
tmcpeak | maybe you were fixing something somebody else started? | 17:10 |
tmcpeak | sigmavirus: | 17:10 |
tmcpeak | sigmavirus: this might be ready to go for starters: https://review.openstack.org/#/c/412343/ | 17:11 |
browne | yeah, bunch of bugs came in. | 17:11 |
tmcpeak | sigmavirus: and this - https://review.openstack.org/412524 | 17:11 |
browne | we'll probably need a new release after fixing them | 17:12 |
tmcpeak | yep | 17:12 |
tmcpeak | I've got some time this week so planning to smash a few | 17:12 |
tmcpeak | Stan and Jamie are sadly MIA and tkelsey is already on break | 17:13 |
*** cleong has quit IRC | 17:15 | |
*** cleong has joined #openstack-security | 17:15 | |
tmcpeak | browne: I can't think of a simple way to test this and I'd rather get it landed than not - https://bugs.launchpad.net/bandit/+bug/1613169 | 17:15 |
openstack | Launchpad bug 1613169 in Bandit "Python 3.x html output on stdout is mangled" [Medium,In progress] - Assigned to Stanislaw Pitucha (stanislaw-pitucha) | 17:15 |
tmcpeak | your comment is valid but I'm just afraid it's going to jam us up here | 17:16 |
tmcpeak | maybe we can add a todo for that unit test? | 17:16 |
*** knangia has joined #openstack-security | 17:16 | |
browne | ok, i can probably let this one slide. testing stdout things is difficult in unit tests | 17:17 |
tmcpeak | browne: awesome | 17:18 |
*** ccneill_ has joined #openstack-security | 17:19 | |
*** ccneill has quit IRC | 17:20 | |
*** corey_ has joined #openstack-security | 17:23 | |
*** cleong has quit IRC | 17:23 | |
*** corey_ is now known as Guest1622 | 17:24 | |
openstackgerrit | Merged openstack/bandit: Detect binary output file (txt/html) https://review.openstack.org/355305 | 17:24 |
sigmavirus | oh, I actually had a test for that locally I think :X | 17:32 |
*** ccneill_ is now known as ccneill | 17:33 | |
openstackgerrit | Eric Brown proposed openstack/bandit: Add functional tests for B308, B321, and B402 https://review.openstack.org/412295 | 17:41 |
*** liverpooler has quit IRC | 17:53 | |
*** liverpooler has joined #openstack-security | 17:55 | |
*** dwyde has quit IRC | 18:02 | |
*** diazjf has quit IRC | 18:18 | |
*** dwyde has joined #openstack-security | 18:34 | |
*** gagehugo has joined #openstack-security | 18:46 | |
*** browne has quit IRC | 19:05 | |
*** openstack has joined #openstack-security | 19:14 | |
dwyde | just wanted to say thanks for all the hard work on Bandit :-) Sorry for filing so many bugs in quick succession! | 19:26 |
*** diazjf has joined #openstack-security | 19:34 | |
openstackgerrit | Travis McPeak proposed openstack/bandit: Fixing partial path detection for Windows https://review.openstack.org/412598 | 19:35 |
tmcpeak | dwyde: thanks for filing them! | 19:35 |
tmcpeak | good stuff! | 19:35 |
*** hello443 has joined #openstack-security | 19:37 | |
*** hello443 has left #openstack-security | 19:38 | |
dwyde | :-) | 19:40 |
tmcpeak | dwyde: I think I'm in agreement with you about rethinking how we're doing severity's for these injections | 19:43 |
tmcpeak | I guess my hesitancy to change is we might seriously break some people | 19:45 |
tmcpeak | that are currently using filters and stuff | 19:46 |
dwyde | mm, I don’t feel super strongly about it | 19:48 |
tmcpeak | I can't explain this logic to myself, lol | 19:52 |
tmcpeak | sigmavirus: in your opinion is change of issue severity a "breaking change"? | 19:54 |
tmcpeak | 1) I want to fix this, 2) I don't want to roll a 2.0 for this | 19:54 |
tmcpeak | I'd say not | 19:55 |
sigmavirus | tmcpeak: so, I'd say changing confidence would be more breaking than not | 19:56 |
*** rcernin has joined #openstack-security | 19:56 | |
sigmavirus | Severity is a little more fluid imo | 19:56 |
tmcpeak | yeah.. | 19:57 |
sigmavirus | but yeah, if people are filtering out low severity and/or low confidence issues and we increase either one, that's kind of a breaking change | 20:02 |
sigmavirus | Then again, I expect projects in OS to be using upper-constraints so that shouldn't be a significant issue for them | 20:02 |
tmcpeak | ok, what I've done is gotten rid of the special characters thing. Anything that would have been medium is now low | 20:04 |
tmcpeak | so this shouldn't break anybody's filtering | 20:04 |
*** diazjf has quit IRC | 20:07 | |
sigmavirus | Right, so I'd nuance my position further in saying taking either severity or confidence from a higher to lower position is absolutely not breaking | 20:09 |
sigmavirus | the opposite, however, is a gray area | 20:09 |
*** knangia has quit IRC | 20:10 | |
tmcpeak | sigmavirus: ack, thank you | 20:18 |
*** jmckind has joined #openstack-security | 20:25 | |
openstackgerrit | Travis McPeak proposed openstack/bandit: Remove checking for special characters in shells https://review.openstack.org/412524 | 20:38 |
dwyde | git archaelogy: ‘tox -e pep8’ was apparently failing for me because bandit.py from 2014 was getting copied from build/ into site-packages/bandit/, which messed with the imports bandit/__init__.py ! | 20:47 |
dwyde | working in a clean tree, lol | 20:47 |
*** jmckind has quit IRC | 20:50 | |
tmcpeak | yikes | 20:52 |
*** jamielennox|away is now known as jamielennox | 21:04 | |
*** v12aml has quit IRC | 21:08 | |
*** v12aml has joined #openstack-security | 21:11 | |
*** gouthamr has quit IRC | 21:17 | |
openstackgerrit | Travis McPeak proposed openstack/bandit: Remove checking for special characters in shells https://review.openstack.org/412524 | 21:18 |
*** Guest1622 has quit IRC | 21:18 | |
*** jmckind has joined #openstack-security | 21:19 | |
*** _elmiko is now known as elmiko | 21:19 | |
*** liverpooler has quit IRC | 21:41 | |
*** browne has joined #openstack-security | 21:53 | |
tmcpeak | sigmavirus: browne: blessings? https://review.openstack.org/#/c/412524/ | 22:01 |
*** dave-mccowan has joined #openstack-security | 22:11 | |
*** knangia has joined #openstack-security | 22:20 | |
*** jmckind_ has joined #openstack-security | 22:32 | |
*** jmckind has quit IRC | 22:34 | |
*** jmckind_ has quit IRC | 22:40 | |
openstackgerrit | David Wyde proposed openstack/bandit: Make Bandit's HTML report pass markup validation https://review.openstack.org/412644 | 23:11 |
*** singlethink has quit IRC | 23:25 | |
*** dwyde has quit IRC | 23:28 | |
*** lamt has quit IRC | 23:32 | |
*** tmcpeak has quit IRC | 23:35 | |
*** dave-mccowan has quit IRC | 23:50 | |
*** tmcpeak has joined #openstack-security | 23:51 | |
tmcpeak | sigmavirus: you still around? | 23:58 |
*** gouthamr has joined #openstack-security | 23:58 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!