*** hongbin has quit IRC | 00:04 | |
*** xin9972 has quit IRC | 00:38 | |
*** browne has quit IRC | 00:56 | |
*** jamielennox is now known as jamielennox|away | 01:02 | |
*** jamielennox|away is now known as jamielennox | 01:17 | |
*** mdong has quit IRC | 01:18 | |
*** markvoelker has joined #openstack-security | 01:27 | |
*** knangia has quit IRC | 02:40 | |
*** xin9972 has joined #openstack-security | 03:13 | |
*** jerrygb_ has quit IRC | 04:02 | |
*** jerrygb has joined #openstack-security | 04:09 | |
*** jerrygb has quit IRC | 04:10 | |
*** xin9972 has quit IRC | 04:30 | |
*** diazjf has joined #openstack-security | 04:49 | |
*** diazjf has quit IRC | 04:50 | |
*** dikonoor has joined #openstack-security | 04:59 | |
*** dikonoor has quit IRC | 05:09 | |
*** jerrygb has joined #openstack-security | 05:11 | |
*** jerrygb has quit IRC | 05:16 | |
*** dikonoor has joined #openstack-security | 05:19 | |
*** jerrygb has joined #openstack-security | 07:00 | |
*** jerrygb has quit IRC | 07:06 | |
*** tesseract has joined #openstack-security | 07:37 | |
*** shohel has joined #openstack-security | 07:49 | |
*** openstackgerrit has quit IRC | 08:03 | |
*** pcaruana has joined #openstack-security | 08:45 | |
*** jerrygb has joined #openstack-security | 09:02 | |
*** jerrygb has quit IRC | 09:08 | |
*** Serlex has joined #openstack-security | 09:10 | |
*** jerrygb has joined #openstack-security | 11:04 | |
*** jerrygb has quit IRC | 11:09 | |
*** openstackgerrit has joined #openstack-security | 11:13 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/424586 | 11:13 |
---|---|---|
openstackgerrit | Merged openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/424586 | 11:20 |
*** dikonoo has joined #openstack-security | 11:22 | |
*** dikonoor has quit IRC | 11:26 | |
*** dikonoo has quit IRC | 12:03 | |
*** gouthamr has joined #openstack-security | 12:13 | |
*** catintheroof has joined #openstack-security | 12:16 | |
*** shohel has quit IRC | 12:34 | |
*** liverpooler has joined #openstack-security | 13:02 | |
*** jerrygb has joined #openstack-security | 13:05 | |
*** jerrygb has quit IRC | 13:10 | |
*** AlexeyAbashkin has joined #openstack-security | 13:16 | |
*** jmckind has joined #openstack-security | 13:18 | |
*** dave-mccowan has joined #openstack-security | 13:18 | |
*** strattao_ has joined #openstack-security | 13:26 | |
*** gouthamr has quit IRC | 13:32 | |
*** flvszch50 has joined #openstack-security | 13:35 | |
*** gouthamr has joined #openstack-security | 14:15 | |
*** pbourke has joined #openstack-security | 14:31 | |
pbourke | hi, does anyone know once a CVE is patched how soon after packages are published to pypi? | 14:32 |
*** jerrygb has joined #openstack-security | 14:44 | |
*** xin9972 has joined #openstack-security | 14:47 | |
*** jerrygb_ has joined #openstack-security | 14:47 | |
*** gouthamr_ has joined #openstack-security | 14:49 | |
*** jerrygb__ has joined #openstack-security | 14:49 | |
*** gouthamr has quit IRC | 14:50 | |
*** jerrygb has quit IRC | 14:51 | |
*** gouthamr_ is now known as gouthamr | 14:51 | |
*** jerrygb_ has quit IRC | 14:52 | |
*** jerrygb has joined #openstack-security | 15:01 | |
*** jerrygb__ has quit IRC | 15:05 | |
*** hongbin has joined #openstack-security | 15:08 | |
*** gouthamr has quit IRC | 15:13 | |
*** markvoelker has quit IRC | 15:18 | |
*** jmckind has quit IRC | 15:21 | |
*** markvoelker has joined #openstack-security | 15:21 | |
*** knangia has joined #openstack-security | 15:25 | |
*** edtubill has joined #openstack-security | 15:36 | |
*** dwyde has joined #openstack-security | 16:00 | |
*** ccneill has joined #openstack-security | 16:04 | |
openstackgerrit | Merged openstack/syntribos: Updated from global requirements https://review.openstack.org/424626 | 16:06 |
*** jerrygb has quit IRC | 16:08 | |
*** jerrygb has joined #openstack-security | 16:09 | |
openstackgerrit | Merged openstack/syntribos: Removing payloads from the repo https://review.openstack.org/424315 | 16:10 |
*** pcaruana has quit IRC | 16:16 | |
sigmavirus | pbourke: you mean publicly disclosed? | 16:26 |
pbourke | sigmavirus: yes, i.e. once its disclosed and patch merged in gerrit | 16:26 |
sigmavirus | pbourke: the answer is *it depends on the team* | 16:27 |
pbourke | makes sense | 16:27 |
sigmavirus | Generally speaking, as long as it's merged there's no pressure to release | 16:27 |
sigmavirus | Given that most CVEs occur in services, the answer is *never* | 16:27 |
sigmavirus | Because the services aren't published to PyPI | 16:27 |
pbourke | what about something like oslo | 16:27 |
sigmavirus | oslo tends to release every week of a cycle before the non-client library freeze | 16:28 |
sigmavirus | (which was last week) | 16:28 |
sigmavirus | (the freeze took effect last week) | 16:29 |
pbourke | guess Im just trying to feel out best practices here, a lot of places will build the services themselves so its easy to apply a patch and rebuild. Not so many will build every oslo lib listed in openstack/requirements | 16:29 |
sigmavirus | pbourke: so the other thing is that a CVE would need to be backported to stable/ocata and a patch release requested for that | 16:31 |
sigmavirus | but yeah, some places do that (openstack-ansible builds the world from scratch) | 16:31 |
pbourke | thanks sigmavirus | 16:33 |
sigmavirus | happy to help pbourke | 16:33 |
*** sicarie has joined #openstack-security | 16:41 | |
*** diazjf has joined #openstack-security | 16:45 | |
*** mdong has joined #openstack-security | 16:54 | |
*** browne has joined #openstack-security | 16:55 | |
*** dwyde has quit IRC | 17:09 | |
*** dwyde has joined #openstack-security | 17:10 | |
*** dave-mccowan has quit IRC | 17:11 | |
*** diazjf has quit IRC | 17:28 | |
*** Serlex has quit IRC | 17:41 | |
*** jmckind has joined #openstack-security | 17:43 | |
*** dwyde has quit IRC | 17:49 | |
*** jmckind_ has joined #openstack-security | 17:50 | |
*** dave-mccowan has joined #openstack-security | 17:51 | |
*** jmckind has quit IRC | 17:51 | |
*** strattao_ has quit IRC | 18:01 | |
*** strattao_ has joined #openstack-security | 18:02 | |
openstackgerrit | Alexandra Settle proposed openstack/security-doc: Updating Object Storage data encryption content https://review.openstack.org/421375 | 18:14 |
*** dwyde has joined #openstack-security | 18:18 | |
*** chyka has joined #openstack-security | 18:20 | |
*** dave-mccowan has quit IRC | 18:30 | |
*** tesseract has quit IRC | 18:39 | |
*** linuxac has joined #openstack-security | 18:43 | |
*** linuxac has left #openstack-security | 18:43 | |
*** diazjf has joined #openstack-security | 18:51 | |
*** aber has joined #openstack-security | 18:55 | |
aber | hallo | 18:55 |
openstackgerrit | Merged openstack/security-doc: Updating Object Storage data encryption content https://review.openstack.org/421375 | 18:57 |
*** dave-mccowan has joined #openstack-security | 18:58 | |
*** aber has left #openstack-security | 18:59 | |
openstackgerrit | Michael Glaser proposed openstack/security-doc: Networking architecture of Security guide implies direct DB conn. https://review.openstack.org/424801 | 19:02 |
*** jmckind has joined #openstack-security | 19:24 | |
*** jmckind_ has quit IRC | 19:27 | |
*** jmckind has quit IRC | 19:28 | |
*** datadog327 has joined #openstack-security | 19:28 | |
*** jmckind_ has joined #openstack-security | 19:34 | |
*** jmckind_ has quit IRC | 19:35 | |
openstackgerrit | Merged openstack/syntribos: Updated pylint rules https://review.openstack.org/424330 | 19:37 |
*** jmckind has joined #openstack-security | 19:38 | |
openstackgerrit | Michael Glaser proposed openstack/security-doc: Networking architecture of Security guide implies direct DB conn. https://review.openstack.org/424801 | 19:48 |
*** diazjf has quit IRC | 19:54 | |
*** diazjf has joined #openstack-security | 19:57 | |
*** jmckind has quit IRC | 20:02 | |
*** jmckind has joined #openstack-security | 20:04 | |
*** xin9972 has quit IRC | 20:05 | |
*** jmckind has quit IRC | 20:08 | |
*** jmckind has joined #openstack-security | 20:09 | |
*** jmckind has quit IRC | 20:14 | |
*** jmckind has joined #openstack-security | 20:14 | |
*** jmckind_ has joined #openstack-security | 20:21 | |
*** jmckind has quit IRC | 20:23 | |
*** diazjf has quit IRC | 20:23 | |
*** jmckind_ has quit IRC | 20:30 | |
*** jmckind has joined #openstack-security | 20:37 | |
*** ccneill has quit IRC | 20:39 | |
*** ccneill has joined #openstack-security | 20:40 | |
*** diazjf has joined #openstack-security | 20:40 | |
*** ccneill has quit IRC | 20:48 | |
*** diazjf has quit IRC | 20:55 | |
*** jerrygb_ has joined #openstack-security | 21:01 | |
*** jerrygb has quit IRC | 21:03 | |
*** jerrygb_ has quit IRC | 21:04 | |
*** dave-mccowan has quit IRC | 21:10 | |
*** jmckind_ has joined #openstack-security | 21:23 | |
*** jmckind has quit IRC | 21:25 | |
*** catintheroof has quit IRC | 21:35 | |
*** catintheroof has joined #openstack-security | 21:35 | |
*** catintheroof has quit IRC | 21:35 | |
*** jmckind has joined #openstack-security | 21:39 | |
*** jmckind_ has quit IRC | 21:40 | |
*** codfection has joined #openstack-security | 21:55 | |
*** jmckind has quit IRC | 22:00 | |
*** dwyde has quit IRC | 22:06 | |
*** datadog327 has quit IRC | 22:15 | |
*** xin9972 has joined #openstack-security | 22:33 | |
*** xin9972 has quit IRC | 22:34 | |
*** codfection has quit IRC | 22:51 | |
*** strattao_ has quit IRC | 22:55 | |
*** strattao_ has joined #openstack-security | 23:01 | |
openstackgerrit | Michael Dong proposed openstack/syntribos: Added support for meta variable JSON files https://review.openstack.org/411415 | 23:09 |
*** mdong has quit IRC | 23:11 | |
*** mdong has joined #openstack-security | 23:11 | |
openstackgerrit | Michael Dong proposed openstack/syntribos: Added support for meta variable JSON files https://review.openstack.org/411415 | 23:13 |
*** edtubill has quit IRC | 23:15 | |
*** strattao_ has quit IRC | 23:23 | |
*** dave-mccowan has joined #openstack-security | 23:33 | |
*** mdong has quit IRC | 23:42 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!