*** markvoelker has quit IRC | 00:09 | |
*** markvoelker has joined #openstack-security | 01:05 | |
*** batshadow has joined #openstack-security | 01:16 | |
*** batshadow has quit IRC | 01:25 | |
*** markvoelker has quit IRC | 01:39 | |
*** gyee has quit IRC | 02:11 | |
*** markvoelker has joined #openstack-security | 02:36 | |
*** batshadow has joined #openstack-security | 02:37 | |
*** batshadow has quit IRC | 02:43 | |
*** markvoelker has quit IRC | 03:09 | |
*** ricolin has joined #openstack-security | 03:50 | |
*** dave-mccowan has quit IRC | 03:54 | |
*** markvoelker has joined #openstack-security | 04:06 | |
*** markvoelker has quit IRC | 04:40 | |
*** pcaruana|afk| has joined #openstack-security | 05:01 | |
*** pcaruana|afk| has quit IRC | 05:04 | |
*** pcaruana has joined #openstack-security | 05:04 | |
*** Luzi has joined #openstack-security | 05:20 | |
*** ricolin has quit IRC | 05:36 | |
*** markvoelker has joined #openstack-security | 05:37 | |
*** markvoelker has quit IRC | 06:10 | |
*** markvoelker has joined #openstack-security | 07:08 | |
*** markvoelker has quit IRC | 07:13 | |
*** tesseract has joined #openstack-security | 07:21 | |
*** trident has quit IRC | 07:31 | |
*** trident has joined #openstack-security | 07:34 | |
*** markvoelker has joined #openstack-security | 08:10 | |
*** markvoelker has quit IRC | 08:14 | |
*** rcernin has quit IRC | 08:23 | |
*** markvoelker has joined #openstack-security | 09:10 | |
*** markvoelker has quit IRC | 09:15 | |
*** markvoelker has joined #openstack-security | 10:11 | |
*** markvoelker has quit IRC | 10:15 | |
*** markvoelker has joined #openstack-security | 12:13 | |
*** markvoelker has quit IRC | 12:17 | |
*** pcaruana has quit IRC | 13:01 | |
*** markvoelker has joined #openstack-security | 13:14 | |
*** markvoelker has quit IRC | 13:18 | |
*** dave-mccowan has joined #openstack-security | 13:39 | |
*** ricolin has joined #openstack-security | 13:45 | |
*** Luzi has quit IRC | 14:02 | |
*** markvoelker has joined #openstack-security | 14:14 | |
*** markvoelker has quit IRC | 14:19 | |
*** ricolin has quit IRC | 14:21 | |
gagehugo | Security SIG meeting in #openstack-meeting in 13 minutes | 14:47 |
---|---|---|
fungi | thanks for the reminder! | 14:59 |
*** gyee has joined #openstack-security | 15:35 | |
fungi | gagehugo: it looks like there's so much stuck in the old moderation queue that i'll need to manually delete the messages off disk, the webui just tells me it "hit a bug" | 15:50 |
gagehugo | heh | 15:51 |
fungi | 787 messages manually discarded for that ml using mailman's command-line discard utility | 15:59 |
fungi | "There are no pending requests." | 16:00 |
fungi | much better | 16:01 |
gagehugo | \o/ | 16:01 |
gagehugo | fungi: edited the description, lemme know how that looks | 16:04 |
gagehugo | or I can post it here as well | 16:04 |
fungi | not quite accurate. it's really used to aggregate updates about launchpad bugs with the "security" bugtag (which aren't necessarily associated with the vmt, more often security hardening fixes and whatnot), and also gerrit changes which have a "security-impact" commit footer (an indication by the change author that there is some possible need for security-related reviewers to look more closely at | 16:06 |
fungi | it) | 16:06 |
fungi | so maybe something like "automated notifications about security-related changes and bug reports" | 16:07 |
gagehugo | yeah that's better | 16:07 |
fungi | the vmt isn't really involved, they use the openstack-announce and openstack-discuss lists to reach out to the community about advisory publication | 16:07 |
fungi | (and also the oss-security ml) | 16:08 |
gagehugo | I meant it as more of the OSSA part in launchpad I think | 16:08 |
gagehugo | but yes | 16:08 |
fungi | i don't think ossa bugs are subscribed to that address, just the security bugtag | 16:13 |
gagehugo | ok | 16:13 |
gagehugo | so not all ossa | 16:13 |
gagehugo | er | 16:13 |
gagehugo | not all security bugs are ossa involved | 16:14 |
*** markvoelker has joined #openstack-security | 16:16 | |
fungi | talking about the security bugtag, not the security bug type. those are separate things in lp | 16:19 |
fungi | if you look at one of the recent messages in the list archive for a bug update, and view the bug, you'll see it has a "tags" area below the description and "security" will be one of them | 16:20 |
fungi | vs in the upper-right corner where the bug type is displayed (public, public security, private, private security) | 16:20 |
*** markvoelker has quit IRC | 16:20 | |
fungi | the openstack vmt's convention is that vulnerabilities have a bug type of public security or private security. other potential security-related bugs just get a bugtag of "security" added to them (and that's what triggers notification to this ml) | 16:21 |
gagehugo | ok | 16:25 |
gagehugo | Would a short sentence about reaching out to the security sig on openstack-discuss be good as well in the -security description? | 16:42 |
fungi | yes, recommend using the [security-sig] tag in subjects | 16:50 |
fungi | alternatively, we can put more of that on https://security.openstack.org/ and just link there? | 16:50 |
gagehugo | yes, both | 16:54 |
fungi | that page could use some sprucing up too | 16:54 |
*** pcaruana has joined #openstack-security | 17:09 | |
*** gyee has quit IRC | 18:04 | |
*** markvoelker has joined #openstack-security | 18:17 | |
*** gyee has joined #openstack-security | 18:19 | |
*** markvoelker has quit IRC | 18:22 | |
*** markvoelker has joined #openstack-security | 19:18 | |
*** markvoelker has quit IRC | 19:23 | |
*** markvoelker has joined #openstack-security | 20:19 | |
*** markvoelker has quit IRC | 20:24 | |
*** pcaruana has quit IRC | 20:36 | |
*** markvoelker has joined #openstack-security | 21:20 | |
*** markvoelker has quit IRC | 21:24 | |
*** dave-mccowan has quit IRC | 22:26 | |
*** rcernin has joined #openstack-security | 22:45 | |
*** tesseract has quit IRC | 22:48 | |
*** dave-mccowan has joined #openstack-security | 22:50 | |
*** dave-mccowan has quit IRC | 23:20 | |
*** markvoelker has joined #openstack-security | 23:22 | |
*** markvoelker has quit IRC | 23:26 | |
*** dave-mccowan has joined #openstack-security | 23:39 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!