Wednesday, 2025-04-23

gouthamrhas anyone seen private bug reports against projects referencing blackduck security scans? 22:35
gouthamrhere's one: https://bugs.launchpad.net/manila/+bug/2106619 ; please share your LP if you'd like to view it.. but i suspect the reporter was running this scanner tool against other OpenStack components too22:36
JayFfungi: ^ is this another case where VMT notifications didn't go out22:36
gouthamrit flags a bunch of python libs specified in our requirements.txt as "operational risk" because they may be outdated, deprecated, vulnerable, or unmaintained22:37
gouthamrah, enlighten me :D 22:37
JayFthat looks 100% invalid to me, I'll run it by VMT22:37
gouthamr++ will add vmt group to the visibility because i could use help 22:38
JayFI can see it; so clearly perms are right. Sometimes the email notifications miss or are very late.22:39
gouthamrack, hey do you know what all tweaks one has to do on Launchpad to properly secure a project? i.e., a dummy's guide to configure security bug stuff properly22:43
gouthamri wanted to bubble that up to PTLs as they're fixing their coresec groups, post this thing merging: https://review.opendev.org/c/openstack/governance/+/94481722:44
JayFgoing to take this up in PM22:47
gouthamrtyty22:47
fungigouthamr: i want to say someone opened one of those for cinder recently as well, and i basically just switched it to public and let them mark it as invalid for the project23:07
fungiah, yes, here: https://bugs.launchpad.net/cinder/+bug/210661523:08
fungiseems virtually identical23:09
fungias for notifications, it's possible that a member of the vmt needs to manually subscribe it to receive notifications for every single bug project in lp that we should be following. i did subscribe us to the "openstack" superproject (which manila is already configured as "part of" in lp), but that alone may be insufficient23:14
fungiwe've added new projects for vmt oversight so rarely that it's possible this is a step that only ttx and markmc remembered to do for the first dozen-ish openstack repos23:15
JayFI got a notification, it just was a good 10 minutes behind the message in IRC23:39
JayFI might propose an update to the VMT process document explicitly calling out certain types of reports as not appropriate for our kind of project23:40

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!