*** ricolin is now known as Guest1112 | 07:59 | |
*** ricolin_ is now known as ricolin | 07:59 | |
*** ricolin_ is now known as ricolin | 14:13 | |
* fungi is around if folks want to meet | 15:02 | |
gagehugo | sorry Im late | 15:17 |
---|---|---|
gagehugo | #startmeeting security | 15:18 |
opendevmeet | Meeting started Thu Mar 3 15:18:01 2022 UTC and is due to finish in 60 minutes. The chair is gagehugo. Information about MeetBot at http://wiki.debian.org/MeetBot. | 15:18 |
opendevmeet | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 15:18 |
opendevmeet | The meeting name has been set to 'security' | 15:18 |
gagehugo | #link https://etherpad.opendev.org/p/security-agenda agenda | 15:18 |
fungi | ohai | 15:19 |
gagehugo | Apologies for the late start, in another meeting and lost track of time | 15:20 |
gagehugo | #topic PTG | 15:20 |
fungi | no worries, i'm in two other meetings at the same time | 15:20 |
gagehugo | heh | 15:20 |
gagehugo | So the PTG is in roughly 1 month | 15:20 |
gagehugo | I was going to cancel next month's meeting since we'll have a session that week anyway | 15:21 |
gagehugo | The current time we are scheduled is Monday April 4th 2100-2300 UTC | 15:21 |
gagehugo | #link https://etherpad.opendev.org/p/security-sig-ptg-zed ptg agenda | 15:21 |
gagehugo | I'll get that etherpad setup today | 15:21 |
gagehugo | and an email sent out | 15:21 |
fungi | thanks! | 15:22 |
gagehugo | #topic open discussion | 15:22 |
gagehugo | I believe the security-specs repo is now officially retired? | 15:22 |
gagehugo | unless I missed a step | 15:23 |
fungi | yes, i think so | 15:23 |
fungi | i remember the governance change merging, which is generally the final step | 15:23 |
gagehugo | ok good | 15:23 |
gagehugo | That's all I had for updates, do you have anything fungi? | 15:24 |
fungi | i may have mentioned it late last year, but i'm noodling on starting a discussion with the community about the security landmine that is horizon's xstatic wrappers for javascript libraries | 15:24 |
gagehugo | oh geez | 15:25 |
fungi | i think the idea at the begining was that it would give us a way to reference js libs from python as dependencies, particularly for testing, but that distros would de-vendor the actual javascript and substitute whatever actual versions of those libs they were already packaging separately | 15:26 |
gagehugo | hmm | 15:26 |
fungi | unfortunately the reality is that they seem to have simply packaged the xstatic wrappers along with the embedded javascript | 15:26 |
gagehugo | ah | 15:27 |
fungi | so openstack has become a redistributor of other people's javascript libs, usually outdated versions of them with known security vulnerabilities | 15:27 |
gagehugo | yeah, that's not great | 15:28 |
fungi | and distros are just shipping those as-is | 15:28 |
fungi | this has come to a head with a recent report to ubuntu about how their packages of things like xstatic-angular and xstatic-jquery have known vulnerabilities, but this gets increasingly complicated because the upstream fixes for those are not things horizon has successfully updated to yet | 15:29 |
fungi | unlike our actual python dependencies, we don't have anything along the lines of global-requirements/upper-constraints to push projects to support latest versions of js libs | 15:30 |
fungi | so they just bitrot and are mostly ignored | 15:30 |
fungi | so anyway, i have concerns. i've had concerns for a long time but the situation seems to be getting worse rather than better | 15:30 |
fungi | what i don't really have yet is good suggestions | 15:31 |
gagehugo | ok | 15:32 |
fungi | if people have ideas they want to share here in the meeting, or reach out to me with after, it's appreciated | 15:32 |
fungi | once i bring the subject to a wider audience on the openstack-discuss ml, maybe there will be more ideas | 15:32 |
gagehugo | That is a good idea | 15:32 |
gagehugo | I think I remember us discussing making an OSSN for log4j last meeting as well? | 15:38 |
fungi | yes, i haven't seen any volunteers there | 15:38 |
fungi | also the vulnerability:managed governance tag removal is on hold waiting for the openstack website to no longer rely on it for the project info pages | 15:38 |
fungi | there's a high priority request in to the webdev contracting company the foundation uses to manage that website to remove those bits | 15:39 |
fungi | but i don't have any eta | 15:39 |
fungi | our (vmt/sig) side though is complete. the security site is updated as is the project team guide | 15:40 |
fungi | er, not the project team guide, sorry, it was the security handbook | 15:40 |
gagehugo | ok cool | 15:40 |
fungi | anyway, it's just the governance change which is still not merged | 15:41 |
fungi | i also noticed, in making that change to the security manual, that it's still referring to the security-analysis repo... we could talk about whether that's still relevant too, or whether it's under-utilized and should be retired | 15:42 |
gagehugo | might be a good PTG discussion | 15:43 |
fungi | i'll add it to the pad | 15:44 |
fungi | it was another outgrowth of the now defunct ossg | 15:45 |
fungi | the remnants of the security sig lack the review bandwidth for what that was designed to be | 15:45 |
gagehugo | :( | 15:46 |
gagehugo | yeah | 15:46 |
fungi | but also nobody seems to be using it anyway | 15:47 |
gagehugo | fungi: anything else for this meeting? | 15:49 |
fungi | nothing else from me, nope | 15:50 |
fungi | thanks for chairing, gagehugo! | 15:50 |
gagehugo | Thanks fungi! | 15:50 |
gagehugo | #endmeeting | 15:50 |
opendevmeet | Meeting ended Thu Mar 3 15:50:45 2022 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 15:50 |
opendevmeet | Minutes: https://meetings.opendev.org/meetings/security/2022/security.2022-03-03-15.18.html | 15:50 |
opendevmeet | Minutes (text): https://meetings.opendev.org/meetings/security/2022/security.2022-03-03-15.18.txt | 15:50 |
opendevmeet | Log: https://meetings.opendev.org/meetings/security/2022/security.2022-03-03-15.18.log.html | 15:50 |
Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!