15:00:08 #startmeeting security 15:00:09 Meeting started Thu May 30 15:00:08 2019 UTC and is due to finish in 60 minutes. The chair is gagehugo. Information about MeetBot at http://wiki.debian.org/MeetBot. 15:00:10 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 15:00:12 The meeting name has been set to 'security' 15:00:19 #link https://etherpad.openstack.org/p/security-agenda agenda 15:00:22 o/ 15:00:30 hi there 15:01:02 hey 15:01:30 give it a few minutes before we start, agenda is light this week so far 15:04:02 \o 15:05:48 #topic Open Discussion 15:05:55 #link https://duo.com/decipher/docker-bug-allows-root-access-to-host-file-system 15:06:05 interesting article fungi linked (yesterday?) 15:07:27 otherwise does anyone have anything? 15:07:40 i have some good news :) 15:08:11 A project I'll be dedicating one workday per week to is updating the security guide docs 15:08:36 nice! 15:08:59 my goal today is to gague how up to date these bugs are https://bugs.launchpad.net/ossp-security-documentation/ 15:09:18 and if there are any obviously missing bugs I should create 15:10:09 excellent, thank you so much for picking this up! 15:10:23 welcome 15:11:06 is there somewhere I can get a handle on what security features have been added during a release? Looking at the release notes is a starting point I imagine 15:11:37 fungi: speaking of security docs, I emailed the security-doc-core group list, haven't heard back from anyone unfortunately 15:11:53 quite a few of the emails were returned as invalid as well 15:12:53 gagehugo: not surprising 15:13:09 nickthetait: maybe start by going through release highlights? and then move on to release notes 15:13:16 okay 15:13:18 * fungi gets the highlights link 15:14:05 for example... 15:14:13 #link https://releases.openstack.org/stein/highlights Stein release highlights 15:14:40 the idea is that projects publish a list of their most important developments in a given release 15:15:00 thats handy 15:15:19 they go back as far as queens, which is precisely where you wanted to start anyway i think? 15:15:34 (the guide claims to be updated for pike already) 15:15:56 yeah 15:16:20 quality of the notes may vary, they're primarily meant as a source for media/analyst types drafting press releases 15:16:50 nice 15:16:50 but at least they provide a starting point, and should correspond to more detailed stuff in release notes and/or project docs 15:17:12 just require a bit of digging to make those connections probably 15:20:03 and its okay for me to start making noise on these bugs? https://bugs.launchpad.net/ossp-security-documentation/ 15:20:19 closing old ones, changing tags, creating new... 15:22:11 I would say sure, start triaging things would be ok 15:22:30 look into existing ones 15:22:46 great 15:23:52 ok that's all the questions I have for now 15:24:19 I'll subscribe and follow up on changes then when I can 15:24:29 thx 15:24:52 yeah, please do whatever you like with the bug reports 15:25:21 i'd like to promise i could subscribe and follow up on them without prompting, but i doubt i have the bandwidth 15:25:34 however, if there's one you feel needs input from me, please do bring it to my attention 15:25:39 I understand that ;) 15:25:55 find me in #openstack-security or feel free to e-mail me or whatever 15:32:51 thanks for coming everyone, have a good weekend! 15:33:11 nickthetait you can ping me as well if needed or email 15:33:17 #endmeeting