15:01:00 #startmeeting security 15:01:00 Meeting started Thu Feb 14 15:01:00 2019 UTC and is due to finish in 60 minutes. The chair is gagehugo. Information about MeetBot at http://wiki.debian.org/MeetBot. 15:01:02 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 15:01:04 The meeting name has been set to 'security' 15:01:42 * fungi is around, just also in tc office hour 15:01:52 #link https://etherpad.openstack.org/p/security-agenda 15:02:04 ping fungi gagehugo lhinds nickthetait browne redrobot 15:02:07 o. 15:02:10 o/ 15:02:15 \o 15:04:23 Only update I have is the security SIG is confirmed for a spot at the denver ptg 15:04:41 fungi redrobot: anything you would like to bring up this week? 15:05:13 nothing on my plate, just here to 👀 15:05:17 container-oriented folks mighth be interested in the runc vulnerability which was reported this week, though odds are they probably are already 15:05:29 true 15:06:03 i know some of the container-related teams like kolla and loci are fielding questions 15:06:27 #link https://shenaniganslabs.io/2019/02/13/Dirty-Sock.html 15:06:35 another thing I saw this week 15:06:48 oof I'm late! 15:07:06 #link https://seclists.org/oss-sec/2019/q1/119 15:07:08 for docker 15:07:29 nickthetait o/ 15:07:36 hey 15:11:52 oh, and there's a discussion on the pypa-dev ml about how (and whether) to deal with unaddressed security vulnerabilities in packages on pypi 15:11:57 lemme get a link 15:12:18 fungi: interesting 15:12:30 a whole category of vulns or different/random ones? 15:12:42 #link https://groups.google.com/forum/#!topic/pypa-dev/9LM_rdiKC5w Handling packages with known vulnerabilities 15:12:47 just in general, yeah 15:14:07 oh, and a couple of interesting security-related threads on distutils-sig this week 15:14:40 #link https://mail.python.org/archives/list/distutils-sig@python.org/thread/ZMJCBP6QFLTR2E26R223LN47OROMBGG3/ Question on Python Package scanning 15:15:00 #link https://mail.python.org/archives/list/distutils-sig@python.org/thread/WPQDP73N7IINXX36UAOG7YDYHD7MYU4X/ API for SHA-256 fingerprints 15:16:32 nice 15:17:32 er, that was the wrong title for that link, was the pip+safety thread 15:17:45 #link https://mail.python.org/archives/list/distutils-sig@python.org/thread/WPQDP73N7IINXX36UAOG7YDYHD7MYU4X/ pip + safety 15:18:08 #link https://mail.python.org/archives/list/distutils-sig@python.org/thread/FLNOENK2525RMHGL7SV2SBUXKSOJHSEZ/ API for SHA-256 fingerprints 15:18:44 that last one gets into the weeds on md5 and misunderstandings on the ways in which it's broken 15:21:09 yeah I added to my to-read list heh 15:21:23 added it* 15:25:49 anything else? 15:25:54 no 15:26:57 btw I said it earlier but the SIG will likely have a spot at the PTG, I don't think the final details have been decided yet 15:27:30 nice 15:29:44 so hopefully we can all see each other there :D 15:30:27 thanks for coming everyone, have a good weekend! 15:30:30 #endmeeting