<@q5sys:matrix.org>
15:00:01
!startmeeting
<@q5sys:matrix.org>
15:00:05
!meetingname security-sig
<@q5sys:matrix.org>
15:00:09
!link Issue Location : https://forge.fedoraproject.org/security/tickets
<@q5sys:matrix.org>
15:00:12
!link Discourse security tagged topics :https://discussion.fedoraproject.org/tag/security
<@py0xc3:fedora.im>
15:00:16
!startmeeting security-sig (2026-06-25)
<@q5sys:matrix.org>
15:00:17
!topic Open floor to discuss anything security related. (2026-06-25)
<@meetbot:fedora.im>
15:00:18
Meeting started at 2026-06-25 15:00:16 UTC
<@meetbot:fedora.im>
15:00:18
The Meeting name is 'security-sig (2026-06-25)'
<@meetbot:fedora.im>
15:00:21
Meeting already in progress
<@q5sys:matrix.org>
15:00:21
!topic Next Meeting (2026-07-02)
<@meetbot:fedora.im>
15:00:21
The Meeting Name is now security-sig
<@q5sys:matrix.org>
15:00:27
!info There are 7 open tickets in the main Security Forge: https://forge.fedoraproject.org/security/tickets/issues
<@q5sys:matrix.org>
15:00:31
!info There are 5 open tickets in the Security Docs Forge: https://forge.fedoraproject.org/security/docs/issues
<@py0xc3:fedora.im>
15:01:13
Regarding the discussion of the security channel, might we try the functions to see if they are useful?
<@thebeanogamer:fedora.im>
15:01:18
!hi
<@py0xc3:fedora.im>
15:01:19
!hi
<@zodbot:fedora.im>
15:01:22
Daniel Milnes: Daniel Milnes (thebeanogamer) - he / him / his
<@zodbot:fedora.im>
15:01:22
Chris (py0xc3): Christopher Klooz (py0xc3) - he / him / his
<@py0xc3:fedora.im>
15:02:18
(I think we just started the meeting twice. I hope that ain't an issue ^^)
<@jforbes:fedora.im>
15:02:22
!hi
<@zodbot:fedora.im>
15:02:23
jforbes: Justin Forbes (jforbes) - he / him / his
<@q5sys:matrix.org>
15:03:40
it might be... but we'll find out I guess.
<@py0xc3:fedora.im>
15:04:05
Ok, I think I will just go ahead and see if/how it works :)
<@py0xc3:fedora.im>
15:04:11
!topic Tickets marked for the meeting
<@py0xc3:fedora.im>
15:04:21
!link Issue Location : https://forge.fedoraproject.org/security/tickets/issues
<@py0xc3:fedora.im>
15:04:26
!forge issue security/tickets 10
<@q5sys:matrix.org>
15:04:28
give me at least 30 seconds or so to start the meeting before you jump on it. lol
<@py0xc3:fedora.im>
15:05:13
I thought I should take over, sorry for the confusion :)
<@py0xc3:fedora.im>
15:05:24
Ok, the forge doesn't work.
<@py0xc3:fedora.im>
15:05:58
!topic Introduce a quorum to mitigate unnecessary meetings (+ consider the meeting label)
<@py0xc3:fedora.im>
15:06:03
!link https://forge.fedoraproject.org/security/tickets/issues/10
<@q5sys:matrix.org>
15:06:40
that would have been an important thing to mention or discuss... if you're just trying to kick me out... maybe... idk... say something to the effect that you want to replace me.
<@py0xc3:fedora.im>
15:07:51
Well, it was discussed to test the new functions, and there was no objection but some +1. I asked if I shall take over and no objection, I just saw you saw it, and it was not open at one past. So I thought that was intended. Sorry :) Feel free to take over
<@q5sys:matrix.org>
15:08:14
test new functions != replace the meeting chairperson without telling them current meeting chair person
<@q5sys:matrix.org>
15:08:46
anyone can use the !commands... it doesn't have to be the person who started the meeting.
<@q5sys:matrix.org>
15:09:43
But getting back on track... does anyone have any thing else to say about https://forge.fedoraproject.org/security/tickets/issues/10 that's not in the ticket?
<@q5sys:matrix.org>
15:09:43
no reason to debate it now though, we can hash all that out later.
<@q5sys:matrix.org>
15:10:49
I personally am in favor of running the meeting even if there are no topics as a sort of 'office hours' for the community. I'm fine with taking that responsibility so there is some regularity to the meetings. Does anyone object to that?
<@py0xc3:fedora.im>
15:11:07
Well, I am fine with everything regarding the meeting. I just would like if people could know in advance about what meetings are, to know if they are relevnat for them or not, when people have to prioritze. At the moment, its a little arbitrary. Otherwise, the average value of a meeting can be low over time and people might have an incentive to no longer join at all.
<@thebeanogamer:fedora.im>
15:11:44
I agree with q5sys, I don't want to get out of the rhythm of having the scheduled slot
<@py0xc3:fedora.im>
15:11:47
I had it twice that i had to prioritze and it wasnt clear if something is discussed about a ticket I'm involved in. So if I'm needed or not.
<@py0xc3:fedora.im>
15:11:55
I'm fine with that.
<@py0xc3:fedora.im>
15:12:20
But improving the structures and make predictable what meetings are about might be worth to increase value. Also to avoid the overhead to find out what to do with the meeting
<@salimma:fedora.im>
15:12:23
!hi
<@zodbot:fedora.im>
15:12:23
Michel Lind ☘ UTC+1 ⏱️: Michel Lind (salimma) - he / him / his
<@salimma:fedora.im>
15:12:27
Half afk
<@q5sys:matrix.org>
15:12:44
Pending Security Tickets are the primary focus of there are people around who want to actively discuss them.
<@q5sys:matrix.org>
15:12:44
Is there a way to flag tickets on forge with priority levels?
<@py0xc3:fedora.im>
15:13:01
Yes, I can create labels for prioritiy
<@q5sys:matrix.org>
15:13:02
on github and gitlab you can create labels... is something similar possible so we coudl label tickets with meeting dates?
<@py0xc3:fedora.im>
15:13:36
I think a label with meeting date would be problematic, as its not intended to be used that way. but different prioritizations ain't an issue
<@py0xc3:fedora.im>
15:14:25
Not sure how it relates to this issue though?
<@py0xc3:fedora.im>
15:14:51
The general use of other teams is to tag for meetings in general, which we already to also, in terms of tagging.
<@py0xc3:fedora.im>
15:15:01
And then discuss what is tagged
<@py0xc3:fedora.im>
15:15:26
The overall number will increase over time. I think the overall number will thus be no longer relevant at some point (if not already now), as all cannot be discussed anyway
<@q5sys:matrix.org>
15:16:29
<@q5sys:matrix.org>
15:16:29
The cons are it will get messy and we'll have to prune labels once they're stale. Im willing to prune the labels weekly. if people think its a good idea but dont want to deal with the mess.
<@q5sys:matrix.org>
15:16:29
So for example, people will know on July 2nd we'll plan to discuss 'foo' and on July 9th, we'll plan to discuss 'bar'. So if they only care about bar and not foo, they could plan what week to attend.
<@q5sys:matrix.org>
15:16:29
The pros of date labels is that will give people time to see it and then prepare to talk about it at that point.
<@q5sys:matrix.org>
15:16:29
IDK if its the best idea, but its an idea. If anyone has a better one I'm all ears. :)
<@q5sys:matrix.org>
15:17:05
There may be a better way to accomplish the same goal.
<@thebeanogamer:fedora.im>
15:17:22
You can set a Due Date on Forgejo tickets
<@py0xc3:fedora.im>
15:17:23
Hmm... Well, we have to create a lot of labels over time, and the system will treat them correspondingly. What you want to achieve might be better served by two meeting labels
<@py0xc3:fedora.im>
15:17:39
one for the meeting and then future-meeting, plus what Daniel said (or, instead, what daniel said ^^)
<@py0xc3:fedora.im>
15:17:56
one for the meeting and then future-meeting, plus what Daniel said (or, justwhat daniel said ^^)
<@py0xc3:fedora.im>
15:18:01
one for the meeting and then future-meeting, plus what Daniel said (or, just what daniel said ^^)
<@py0xc3:fedora.im>
15:18:52
The point would be just to make it predictable what is to be discussed, and the structure of the meetings. Saves time, and makes clear to people what the meeting is about to maximize value, incl. when they have to prioritze
<@q5sys:matrix.org>
15:18:55
would due date be used for the 'meeting date' or...? as a dev that means... "this issue better be resolved by then" type of thing.
<@py0xc3:fedora.im>
15:19:40
Well, we could decide to use it that way. But I think it will be confusing for others and those who are also in other teams, as usually its not intended to be "due for meeting"
<@py0xc3:fedora.im>
15:20:42
I mean, the meeting label should suffice, as for other teams too? I think it is realistic to roughly predict a realistic number, and if one remains at the end, well, we cannot be prepared for everything
<@py0xc3:fedora.im>
15:21:45
The tickets can be used to create a clear structure, with !topic & !link to the tickets, and then just the !topic open floor at the end. Also for reviews etc
<@py0xc3:fedora.im>
15:22:37
I'm fine with anything that gives me some hint what a meeting is about in advance :)
<@q5sys:matrix.org>
15:22:44
crazy idea... anyone know how open the maintainer of forge is to feature requests/prs? Maybe there's a feature we could create and file a PR for? What is forge written in?
<@py0xc3:fedora.im>
15:23:21
I think Go + JavaScript
<@py0xc3:fedora.im>
15:23:59
Feature requests are possible. Prioritization is implemented by most teams I know by additional labels. Keep in mind we can label a ticket with several labels. So that would not conflict, if that is the issue?
<@q5sys:matrix.org>
15:24:57
I guess we could label 'next meeting'
<@py0xc3:fedora.im>
15:25:39
you mean additional to "meeting"?
<@py0xc3:fedora.im>
15:26:53
Unless something is prioritized urgent, I would have guessed its just number by number or so.
<@q5sys:matrix.org>
15:26:55
just saying 'meeting' could mean this week, next week, the week after next.
<@q5sys:matrix.org>
15:26:55
im just trying to give people an idea of which meeting something might be in. based on your concern not to waste peoples time... or to have them prioritize their schedule for things.
<@py0xc3:fedora.im>
15:27:01
But I have no problem with it
<@py0xc3:fedora.im>
15:27:20
Well, thats what we have the existing meeting label for. Its just not used in most meetings
<@py0xc3:fedora.im>
15:27:29
Te
<@q5sys:matrix.org>
15:27:30
IDK how best to label things so people can plan their schedule... since using dates isn't liked.
<@q5sys:matrix.org>
15:28:26
or... we could have a single ticket that is a meeting outline that we just update.
<@py0xc3:fedora.im>
15:28:59
I would try to align with other teams actually. Do what people are used to
<@q5sys:matrix.org>
15:29:05
the OpenZFS leadership meeting has a google doc which we update for our monthly call with all the things we want to discuss on what date, so people know when to attend for discussion around thier PR.
<@py0xc3:fedora.im>
15:29:05
Not sure what others think?
<@q5sys:matrix.org>
15:29:22
but I wouldnt want to use something off Fedora's infra.
<@py0xc3:fedora.im>
15:29:33
I have no problem with it, I just don't want to be forced to create a google account :)
<@py0xc3:fedora.im>
15:29:41
my preference too :)
<@py0xc3:fedora.im>
15:29:46
In the Docs we used a Discourse topic
<@py0xc3:fedora.im>
15:29:51
for every week
<@py0xc3:fedora.im>
15:30:07
But I think several engineers dont like discourse
<@q5sys:matrix.org>
15:30:20
Im one of them. lol
<@q5sys:matrix.org>
15:30:33
i'll use it begrudglingly... but I dislike it for many reasons
<@py0xc3:fedora.im>
15:31:35
Another suggestion, that might be less confusing for people used to other work flows:
<@py0xc3:fedora.im>
15:33:05
keeping the meeting label, create an additional urgent tag, and then do the meeting one by one with the meeting labeled topics. People can decide themselves and make their own guess if "their" tickets are likely to be processed or not (e.g., if they are at the 1st or 10th place of the marked tickets). Exception: if "meeting" labeled topics are marked also as "urgent", these get before those without.
<@py0xc3:fedora.im>
15:33:26
I THINK that is widely compatible to what other teams do, to not re-invent the wheel, but still gives a good expectation of what a meeting will be about ?
<@py0xc3:fedora.im>
15:33:55
If the then also use the !topic functions and such, we might further improve the summaries etc over time and get a better structure
<@py0xc3:fedora.im>
15:34:08
If the then also use the !topic functions and such, we might further improve the summaries etc over time and get a better structure (also within/during the meeting)
<@py0xc3:fedora.im>
15:34:13
Just a thought in between :)
<@py0xc3:fedora.im>
15:34:48
This exploits the numbering of tickets, #1, #2 etc
<@q5sys:matrix.org>
15:40:02
Some of these things are really only going to applicable once we actually have a ton of things going on and a ton of activity.
<@q5sys:matrix.org>
15:40:02
Everyone is all excited to do stuff and build stuff initially... but after a few years the fun is gone and its just a slog.
<@q5sys:matrix.org>
15:40:02
I dont want to see us have the same problem, because that causes burnout and then a project or team will loose people.
<@q5sys:matrix.org>
15:40:02
I just worry that we're create so much structure that it becomes cumbersome to use with the minimal activity we have. Back in the day when I was a part of the PC-BSD/TrueOS Project... we tried to run regular meetings and a ton of structure was set up. But when it was the same 5-8 people every time, with nothing new to say that wasnt already said in the normal chat... it got to become a PITA to manage all that infra. It just became a digital form of paper pushing with no benefit.
<@q5sys:matrix.org>
15:40:02
I dont really care what structure is put in place to use. I'll use whatever even if I dont really like it. So if you can come up with a plan, cool.
<@q5sys:matrix.org>
15:40:02
I'm not suggesting we dont think about this stuff... we absolutely should. But right now I'm just trying to get people to realize the team exists and they can come talk to us.
<@q5sys:matrix.org>
15:40:02
Which currently we dont. :(
<@py0xc3:fedora.im>
15:40:07
I think it might make sense to wait some minutes to see what others say, we (mostly me:) talked already too much :D
<@q5sys:matrix.org>
15:40:31
Anyone can jump in at any time...
<@py0xc3:fedora.im>
15:40:41
Sure, I'm still reading your post :) mom
<@q5sys:matrix.org>
15:40:44
and of course they can comment later if they review the chat log or meeting notes.
<@q5sys:matrix.org>
15:43:46
So this time... I'm trying to take all the day to day monotony on myself, so maybe this time it can last... and let other people do the exciting bits as they want... so they dont have the pressure of the monotonous stuff.
<@q5sys:matrix.org>
15:43:46
People get excited... want to jump in... then the day to day monotony settles in and people find other things they're more excited to do.
<@q5sys:matrix.org>
15:43:46
<@q5sys:matrix.org>
15:43:46
The reason the security team has been a start/stop thing over more than the last decade... is because of the excitement/burnout cycle.
<@py0xc3:fedora.im>
15:44:43
I think I would leave it for others to comment. The only thing I might add is the perspective of mine: the value of the meetings for me is on average quite low, and when I have to prioritize, I started to give this a low priority, because it's not predictable for me what is going on, and when I did otherwise in the past, the meeting was once started without any topic at all. So, I could have prioritized something else. Lost time. My feeling is the number of people has decreased, and there is a chance I can understand why. Security is broad, and not every security topic is relevant for everybody. That's the general issue :) Creating new structures is what you said, so I tend to stick with what works fine for others :)
<@py0xc3:fedora.im>
15:45:13
I think I would leave it for others to comment. The only thing I might add is the perspective of mine: the value of the meetings for me is on average quite low, and when I have to prioritize, I started to give this a low priority, because it's not predictable for me what is going on, and when I did otherwise in the past, the meeting was once started without any topic at all. So, I could have prioritized something else. Lost time. My feeling is the number of people has decreased, and there is a chance I can understand why. Security is broad, and not every security topic is relevant for everybody. That's the general issue :) Creating new structures is what you said, so I tend to stick with what works fine for other teams :)
<@thebeanogamer:fedora.im>
15:45:28
Sorry I got pulled away for $realjob
<@thebeanogamer:fedora.im>
15:45:37
Slightly concerned that we're still on this topic
<@q5sys:matrix.org>
15:46:32
No worries, the real job is what pays the bills. It should take priority.
<@py0xc3:fedora.im>
15:46:35
Yeah we definitely should not start the second ticket today :)
<@py0xc3:fedora.im>
15:47:24
Well, if no one has points, I guess we might leave the security meetings as they are for now ? Or leave the ticket open? Not sure
<@q5sys:matrix.org>
15:48:40
While we do have some things we want to do, we dont really have a roadmap of work.
<@q5sys:matrix.org>
15:48:40
What works for other teams is a good place to start... but security work is very different than say infra work, or design work where they are clear plans/goals for tasks... a lot of what we do is reactive. Sure there's some project work, but that's less than everything else.
<@q5sys:matrix.org>
15:49:15
So we can take what works for others, but we'll have to adjust it for the differing nature of what things come our way.
<@q5sys:matrix.org>
15:50:02
Generally speaking, if a ticket comes in, we should discuss it in the next meeting... if its a large issue where many people will want to comment on it. We need some way to let people know when we're going to talk about it. If a discourse post is the best way to do that, I'm fine with that. If its a ticket in our forge... I'm fine with that too.
<@q5sys:matrix.org>
15:50:51
What would be nice is input from more than the three of us... about what would work for the people we want to attract to become active.
<@jforbes:fedora.im>
15:54:52
Sorry, I typically have another meeting during this time as well. I am mainly around in case there are kernel questions. I will say that these meetings do seem perhaps more frequent than is needed.
<@q5sys:matrix.org>
15:56:11
Yea the mix between tickets/issues and security team stuff... and 'Open Office Hours'... makes it a bit awkward.
<@q5sys:matrix.org>
15:56:54
I had thought about doing "Official meetings" every other and then on the off weeks have the 'Security team office hours' at the same time. But that seemed like more to juggle in peoples minds wondering which week is which.
<@jforbes:fedora.im>
15:57:40
Well, if we post agenda before each, that would take away that issue
<@py0xc3:fedora.im>
15:58:37
that was originally the idea of the meeting labels
<@py0xc3:fedora.im>
15:58:49
but its just one way to achieve that
<@py0xc3:fedora.im>
15:59:01
I'm happy with every way that achieves the goal :)
<@q5sys:matrix.org>
15:59:26
And with security being reactive... if something does happen, we'll want to do something that week and not wait for the next. So it makes sense to just keep doing it every week.
<@q5sys:matrix.org>
15:59:26
And my plan was... if there's nothing team wise to discuss... I can ride solo if there's people in the community that wander in.
<@jforbes:fedora.im>
15:59:51
The thing with labels is people have to come looking to our issue tracker. Posting a meeting agenda similar to what other SIGs and meetings do is a push notification for people who care to see it on discuss/email
<@q5sys:matrix.org>
15:59:54
an agenda seems to be the easiest and quickest fix
<@py0xc3:fedora.im>
16:00:43
yeah, someone needs to prepare it in advance though :) Maybe a day or so
<@jforbes:fedora.im>
16:00:51
correct
<@py0xc3:fedora.im>
16:00:53
discourse + matrix might be useful
<@py0xc3:fedora.im>
16:01:01
as these are the major channels
<@py0xc3:fedora.im>
16:01:29
keeping it aligned, the people who dislike discourse might review it on matrix. I would assume for emails the sig is too "loose" at this time (?)
<@py0xc3:fedora.im>
16:02:37
putting on the agenda just the tickets that are marked?
<@py0xc3:fedora.im>
16:02:48
(I have to leave soon...)
<@q5sys:matrix.org>
16:03:10
There is a security mailing list we could also push to unless it finally got nuked from being inactive
<@q5sys:matrix.org>
16:03:33
if that's still around we could push to all three matrix/discourse/ml
<@py0xc3:fedora.im>
16:03:34
I think it is archived
<@py0xc3:fedora.im>
16:03:46
but not 100% sure off the cuff
<@py0xc3:fedora.im>
16:04:32
Ok, let's start to publish an agenda on the day before meeting ? matrix + discourse ?
<@py0xc3:fedora.im>
16:04:39
We can see what proves useful to be contained
<@py0xc3:fedora.im>
16:04:53
On Docs it could be updated and people coud post, and see how it evolves
<@q5sys:matrix.org>
16:05:44
Sounds good to me. We can continue the discussion around the best way to notify people in the security channel.
<@q5sys:matrix.org>
16:06:08
I'll close out this meeting for now if there's not a final comment someone wants to get in on the record.
<@py0xc3:fedora.im>
16:06:09
!agreed to publish an agenda in matrix and discourse about a day before the meetings
<@py0xc3:fedora.im>
16:06:18
Im fine
<@py0xc3:fedora.im>
16:06:25
do you want to publish it?
<@py0xc3:fedora.im>
16:06:49
I could start it if you want, just adding open tickets or so, and see what people say or want to add. But you can do it either. I'm fine with anything
<@q5sys:matrix.org>
16:07:25
doesn't matter to me, if you want to take that on... that's fine with me. Or I can do it.
<@q5sys:matrix.org>
16:08:23
we can hash out the details in the sec channel, others that aren't avail for this meeting might have other good ideas we might want to use.
<@q5sys:matrix.org>
16:08:51
(this was somewhat easier when we had meetings in that channel so it wasnt jumping back and forth... but anywho...)
<@q5sys:matrix.org>
16:09:11
!endmeeting