<@q5sys:matrix.org>
15:00:36
!startmeeting
<@meetbot:fedora.im>
15:00:39
Meeting started at 2026-07-02 15:00:36 UTC
<@meetbot:fedora.im>
15:00:39
The Meeting name is 'Fedora Meeting 3'
<@salimma:fedora.im>
15:00:43
!hi
<@q5sys:matrix.org>
15:00:44
!meetingname security-sig
<@zodbot:fedora.im>
15:00:45
Michel Lind ☘ UTC+1 ⏱️: Michel Lind (salimma) - he / him / his
<@py0xc3:fedora.im>
15:00:52
!hi
<@zodbot:fedora.im>
15:00:52
Chris (py0xc3): Christopher Klooz (py0xc3) - he / him / his
<@q5sys:matrix.org>
15:01:08
!link Issue Location : https://forge.fedoraproject.org/security/tickets
<@meetbot:fedora.im>
15:01:09
The Meeting Name is now security-sig
<@q5sys:matrix.org>
15:01:13
!link Discourse security tagged topics :https://discussion.fedoraproject.org/tag/security
<@decathorpe:fedora.im>
15:01:16
!hi
<@q5sys:matrix.org>
15:01:17
!topic Open floor to discuss anything security related. (2026-07-02)
<@zodbot:fedora.im>
15:01:17
Fabio Valentini 🌈: Fabio Valentini (decathorpe) - he / him / his
<@q5sys:matrix.org>
15:01:19
!topic Next Meeting (2026-07-09)
<@q5sys:matrix.org>
15:01:21
!info There are 7 open tickets in the main Security Forge: https://forge.fedoraproject.org/security/tickets/issues
<@q5sys:matrix.org>
15:01:23
!info There are 6 open tickets in the Security Docs Forge: https://forge.fedoraproject.org/security/docs/issues
<@q5sys:matrix.org>
15:01:46
!info Agenda: https://discussion.fedoraproject.org/t/security-sig-meeting-agenda-for-the-meeting-on-02-07-2026/195393/1
<@rzhukov:matrix.org>
15:02:36
Hi folks, do we have a room for a quick intros?
<@decathorpe:fedora.im>
15:02:41
is the topic now "next meeting" or "open floor"?
<@py0xc3:fedora.im>
15:02:58
theoretically, 1.1 of the agenda :)
<@decathorpe:fedora.im>
15:03:31
!topic Introduce a quorum to mitigate unnecessary meetings and use "meeting" label
<@py0xc3:fedora.im>
15:03:40
I wasn't sure if I should remove the meeting tag so I left it. I think we might just see how the agenda develops and if it serves its need. People can decide now in advance if the meeting is relevant for them and if they are needed.
<@py0xc3:fedora.im>
15:03:40
<@py0xc3:fedora.im>
15:03:40
If people want, it could be discussed if a quorum for decisions is to be introduced. At the moment, every 1-person-project could become a Security SIG project if no one objects. But given that only known and trusted contributors are SIG members, I see this not critical. So I leave it to others if there is need to discuss any of this...
<@decathorpe:fedora.im>
15:03:41
I'm +1 but I'm biased since this is my idea :)
<@ljavorsk:fedora.im>
15:04:33
How can we join the Security SIG?
<@decathorpe:fedora.im>
15:04:41
sorry, there should be room for introductions, I didn't want to ignore you
<@decathorpe:fedora.im>
15:04:59
just confusion about what is now actually the current !topic
<@py0xc3:fedora.im>
15:05:03
ups. didn't see the message. sure.
<@rzhukov:matrix.org>
15:05:22
No probs, just let me know when there is a right moment :)
<@decathorpe:fedora.im>
15:05:40
we can do a !topic Introductions next
<@rzhukov:matrix.org>
15:06:22
Great!
<@rzhukov:matrix.org>
15:06:34
Hi folks, first time here, I'd like to introduce myself. 👋 I'm Roman, Open Source Security Lead from Red Hat, contributor to open-source projects and old-nerdy security champion, largely in Linux Foundation/OpenSSF ecosystem. I might have met some of you at the fantastic Flock event last month in Prague, where we were doing the EU CRA workshop together with the Fedora community.
<@rzhukov:matrix.org>
15:06:49
As we are all entering in the AI craziness and post-Mythos Era AND navigating the EU CRA (https://forge.fedoraproject.org/council/tickets/issues/559), together with a few colleagues of mine (Lukas, Michal, Anwesha, Jaroslav) I’d like to join the Fedora Security SIG to better understand the current challenges community is experiencing at the moment. My primary goal would be to understand what help might be needed (resources, tools, additional pair of eyes, brains, etc.) to make sure we implement the dev-centric, practical and meaningful security measures while reducing friction. I led security efforts for a few open source projects in the past, and I understand the pain developers experience. To be honest with you, I think we have the good momentum to make security (and yes, compliance, sic) right.
<@rzhukov:matrix.org>
15:07:20
Long one, but I'm done, thx :)
<@rzhukov:matrix.org>
15:07:46
LMK if/when we would like to dive into some specifics (maybe future meetings)
<@decathorpe:fedora.im>
15:08:52
welcome!
<@decathorpe:fedora.im>
15:09:05
should we do a round of introductions for others too?
<@salimma:fedora.im>
15:09:22
welcome! and, yes, we should intro ourselves
<@decathorpe:fedora.im>
15:10:14
!topic Introductions
<@decathorpe:fedora.im>
15:10:19
let's make it official then
<@jforbes:fedora.im>
15:11:50
I am Justin, the Fedora kernel maintainer.
<@decathorpe:fedora.im>
15:12:06
my other contributions are primarily related to Rust packaging and / or security related through my work handling security issues for the Rust SIG and my involvement with OpenPGP / Sequoia-PGP - and the "Adopt PURL" change proposal some of you have seen
<@decathorpe:fedora.im>
15:12:06
my FAS is `decathorpe`, I am now a FESCo, Fedora Council, and Packaging Committe member
<@py0xc3:fedora.im>
15:13:46
I'm Chris, currently mostly active in the Security SIG and the Moderation Team, indirectly also QA. Noteworthy amount of my time is maintaining the #kernel tag in ask.fedora and work with users to identify if they found bugs, do triage, and if so, work with upstream to fix kernel bugs, test patches, to relief our kernel team as far as possible :) Recently I was working with a vendor to get their devices Fedora Ready (which was mostly fixing kernel bugs and optimizing their firmware scripts for fedora). So one time stuff like that also makes much of my contribution times. Doing also some crypto stuff, but that "should" be now mostly integrated in the Security SIG :)
<@salimma:fedora.im>
15:13:48
I'm Michel, on FESCo and the packaging committee in addition to this, and CentOS Hyperscale and Proposed Updates SIG (the latter is partially security focused so there's a strong overlap here)
<@salimma:fedora.im>
15:13:48
<@salimma:fedora.im>
15:13:48
I maintain too many packages, and so am interested in tooling that help reduce packaging toil and make it easier to make sure packages are properly maintained and secure
<@q5sys:matrix.org>
15:14:03
I'm the current dev of the webzfs, Lumina Desktop, and a bunch of other small projects. I also am the producer of the podcast 'BSDNow', and the DM Radio show 'Ask Noah Show' (Linux/sysadmin radio show) on KEQQ FM.
<@q5sys:matrix.org>
15:14:03
I worked in security a while ago, but these days I do less security and mostly do whatever needs doing.
<@q5sys:matrix.org>
15:14:03
I'm JT (fas = q5sys), Ive been an open source (Linux/FreeBSD) Dev for over two decades now. I'm the release maintainer for 5 Fedora Releases (Security-Lab, Jam, Games, Astronomy, Scientific Lab).
<@ljavorsk:fedora.im>
15:15:24
Looking forward to work with all of you :)
<@ljavorsk:fedora.im>
15:15:24
I can also introduce myself. My name is Lukas, working in Red Hat Product Security as an Incident Commander for the CRA. I've been also working as an Engineer within Red Hat so I have a lot of background in that as well (made it to Fedora Proven Packager and Fedora Packager Sponsor) so I can translate those pains to Prodsec to help ease the process hopefully.
<@decathorpe:fedora.im>
15:17:38
FWIW I think you would both be welcome as Fedora security-sig members
<@decathorpe:fedora.im>
15:18:10
adding you should be straightforward if there are no objections (just somebody with the necessary powers pushing a few buttons)
<@py0xc3:fedora.im>
15:18:43
+1 -> we have three people here with the powers :)
<@py0xc3:fedora.im>
15:18:53
wait, 4 xD
<@mfindra:matrix.org>
15:18:54
hey, I;ve already intorduced myself in the antoher channel but copying here: I'll be working with you (and @Lukas Javorsky) on CRA and other Product Security–related topics. I've been working in Product Security for a while now, so if you have any questions, don't hesitate to ask.
<@decathorpe:fedora.im>
15:19:56
+1 to adding more members to the SIG!
<@rzhukov:matrix.org>
15:20:41
I'll go once again to fit into after the intros were tagged :D
<@rzhukov:matrix.org>
15:20:59
Hi folks, first time here, I'd like to introduce myself. 👋 I'm Roman, Open Source Security Lead from Red Hat, contributor to open-source projects and old-nerdy security champion, largely in Linux Foundation/OpenSSF ecosystem. I might have met some of you at the fantastic Flock event last month in Prague, where we were doing the EU CRA workshop together with the Fedora community. Happy to join the group and help as much as I can
<@decathorpe:fedora.im>
15:21:24
so I think the only thing we'd need to know are your usernames in the fedora accounts system (if they're not the same as your matrix handle)
<@ljavorsk:fedora.im>
15:23:09
ljavorsk
<@q5sys:matrix.org>
15:23:24
rzhukov The Red Hat structure is kinda crazy to anyone not on the inside. Are you a direct report to Vincent? I can never figure out the hierarchy. haha (you dont have to answer if you dont want to, You can ignore me being nosy. haha)
<@rzhukov:matrix.org>
15:24:41
😂 sure, I'm actually part of Open Source Office which is part of Global Engineering which means peers to Vincent's Products Security org.
<@salimma:fedora.im>
15:25:20
it's turtles all the way down :P
<@salimma:fedora.im>
15:25:38
rzhukovdo I remember correctly from your CRA presentation at FRCL that you're based in Ireland?
<@salimma:fedora.im>
15:25:44
I should visit that office sometime, I'm in Dublin
<@decathorpe:fedora.im>
15:26:08
added - you should show up as member at https://forge.fedoraproject.org/security after you log in I think
<@ljavorsk:fedora.im>
15:26:47
Thank you :)
<@rzhukov:matrix.org>
15:26:48
Yes, you got it right! Sure, will be happy to either host you in our office or to grab a coffee/beer otherwise in the city center
<@q5sys:matrix.org>
15:26:50
Vincent is a cool. I've interviewed him for the radio show the past few years at Summit. I might have to bug John Terrill to get an interview with you sometime in the future. haha
<@mfindra:matrix.org>
15:27:16
m-findra
<@rzhukov:matrix.org>
15:27:32
No probs, John is the right person to get PR blessings, yes 😁
<@salimma:fedora.im>
15:28:54
likewise if you want to visit Dublin
<@decathorpe:fedora.im>
15:29:14
ok, I think the memberships should be sorted out. a login (or log-out and log-back-in) should have you show up as members on https://forge.fedoraproject.org/security
<@salimma:fedora.im>
15:29:16
TIL we can use dashes in FAS names :)
<@py0xc3:fedora.im>
15:29:20
I might come back to then at some time :P
<@salimma:fedora.im>
15:29:25
I still meant to rename mine but I'm scared it will break something
<@py0xc3:fedora.im>
15:29:31
I might come back to that at some time :P
<@mfindra:matrix.org>
15:29:47
I created mfindra account on wrong email that doesnt exist :D
<@rzhukov:matrix.org>
15:30:55
We actually can do both 😁. We rent a space in WeWork just right besides Temple Bar
<@decathorpe:fedora.im>
15:31:14
do we want to continue with the topics from the meeting agenda? or move that to after open floor?
<@py0xc3:fedora.im>
15:31:30
Fine with both. there is nothing urgent I think.
<@q5sys:matrix.org>
15:32:03
Ok with intros out of the way and everyone added to the SIG that needs to be added (Thanks Fabio Valentini 🌈 ) The next topic would be our discussion around https://forge.fedoraproject.org/security/tickets/issues/10 which seems to me to be mostly handled. We'll be publishing the agenda every week now; anyone can show up that wants to show up. If there's nothing to discuss or anything pressing, the meeting time will be an 'open office hours' meeting
<@py0xc3:fedora.im>
15:32:33
I think the agenda serves well to let people know in advance if a meeting is relevant for them and if they are needed. The remaining question is actually only if a quorum is to be introduced.
<@decathorpe:fedora.im>
15:33:01
yeah, making office hours if there's no topics on the agends sounds good ot me
<@py0xc3:fedora.im>
15:33:02
(if others agree with the first ^^)
<@salimma:fedora.im>
15:33:05
I think quorum makes sense esp, we can just tweak the threshold as we go along
<@decathorpe:fedora.im>
15:34:42
there are now 13 members, not sure how many people will actually regularly show up to meetings though. so maybe start low with the quorum limit, or wait and see how attendance at meetings turns out?
<@ljavorsk:fedora.im>
15:35:04
Start with 3-4?
<@decathorpe:fedora.im>
15:35:14
yeah, making office hours if there's no topics on the agenda sounds good to me (just realized I can't spell today)
<@ljavorsk:fedora.im>
15:35:46
Also it's holliday season, probably a lot of us will be somewhere at the beach this time :D
<@rzhukov:matrix.org>
15:36:03
+1 for publishing agenda in advance. I was actually looking for it before joining today :) And it'd be nice to flag something like [decision required] to collect rsvps
<@decathorpe:fedora.im>
15:36:05
yeah 3 or 4 should be OK to start with, adjusting later is always possible
<@py0xc3:fedora.im>
15:36:07
I think 3-4 is a reasonable number to start with. Shall we use that number only as meeting quorum or generally as min. for decisions? (e.g., also for tickets etc?)
<@py0xc3:fedora.im>
15:36:39
I tend to like both tbh :)
<@decathorpe:fedora.im>
15:36:46
I think it would make sense for formal decisions, but if meetings turn into informal office hours anway I don't think we need a lower limit for those.
<@q5sys:matrix.org>
15:37:59
office hours meetings wouldnt be taking votes
<@decathorpe:fedora.im>
15:38:11
that too.
<@q5sys:matrix.org>
15:38:12
most they would be doing would be creating tickets
<@decathorpe:fedora.im>
15:38:32
moar tickets!
<@salimma:fedora.im>
15:38:43
so... accumulating work for the next quorum meeting. I see ;)
<@decathorpe:fedora.im>
15:40:33
<@decathorpe:fedora.im>
15:40:33
so to summarize (correct me if I got something wrong):
<@decathorpe:fedora.im>
15:40:33
- Meeting Agenda is sent out in advance, if no topics, meeting turns into open-floor / office hours.
<@decathorpe:fedora.im>
15:40:33
- Formal decisions require votes from at least three SIG members
<@decathorpe:fedora.im>
15:41:34
sounds good to me 👍️
<@py0xc3:fedora.im>
15:41:34
+1
<@ljavorsk:fedora.im>
15:41:49
+1
<@jforbes:fedora.im>
15:41:58
+1
<@decathorpe:fedora.im>
15:42:03
<del>sounds good to me 👍️</del> +1
<@decathorpe:fedora.im>
15:43:39
!agreed Agenda for upcoming meetings will be published in advance. Formal decisions require votes from at least three SIG members. (+4, 0, -0)
<@rzhukov:matrix.org>
15:43:50
+1
<@decathorpe:fedora.im>
15:43:50
let's use those fancy bot features when they're there 😁
<@decathorpe:fedora.im>
15:44:23
I think that concludes this topic?
<@py0xc3:fedora.im>
15:44:32
think so
<@decathorpe:fedora.im>
15:47:01
Chris (py0xc3): want to move on to the Docs topic?
<@py0xc3:fedora.im>
15:47:12
Yeah sure. Could be quick too.
<@py0xc3:fedora.im>
15:47:34
!topic Shall the Security Docs in the Security SIG’s repo consolidate all security topics in general (and maybe also integrate other Security Docs still in Quick Docs or so), or only contain Docs that are jointly/reliably maintained by the Security SIG?
<@py0xc3:fedora.im>
15:47:42
→ This contains the underlying question if it is a “Security Docs” or “Security SIG Docs”
<@py0xc3:fedora.im>
15:47:50
That came up when I evaluated where to put the hardening docs in the changed situation. Quick Docs or Security Docs. It raises this question. I thought its worth to be raised once to see if everyone is on the same page. I have no strong opinion about it, but I tend to emphasize our docs as Security **SIG** Docs, to avoid they develop like so many Docs in the structures of Fedora when created/maintained by 1 (a reason for the problematic reputation of Fedora Docs).
<@decathorpe:fedora.im>
15:48:46
Counter-question: Who *would* maintain Security non-SIG Docs?
<@py0xc3:fedora.im>
15:49:46
That's the problem :) So far discussions considered "is it security? if so, put it to our docs". That might lead to us integrating all related Docs over time. And it could be questioned if we can maintain all that.
<@decathorpe:fedora.im>
15:50:10
Counter-question: Are the docs that are currently in the quick docs better maintained? ;)
<@q5sys:matrix.org>
15:50:57
if its related to security in general in Fedora == Security Docs.
<@q5sys:matrix.org>
15:50:57
if its realted to the SIG itself == Security SIG Docs
<@q5sys:matrix.org>
15:50:57
My take:
<@py0xc3:fedora.im>
15:51:01
No they ain't. Which is a reason for their reputation :) I would prefer we take another approach. So taking only Docs that are maintained more reliably by the team, not only individuals, or no one at all (which is often the result at some time when it starts with 1 )
<@q5sys:matrix.org>
15:51:38
As to who would maintain Security Docs... who wants to volunteer. lol
<@ljavorsk:fedora.im>
15:51:46
So there are 3 types of docs?
<@ljavorsk:fedora.im>
15:51:46
1) Security Docs
<@ljavorsk:fedora.im>
15:51:46
3) Quick Docs
<@ljavorsk:fedora.im>
15:51:46
2) Security SIG Docs
<@py0xc3:fedora.im>
15:52:09
That's it :) I would leave that in the quick docs, unless what we can maintain. So taking another approach.
<@py0xc3:fedora.im>
15:52:22
the question we have a docs repo, but not yet really decided which of the two approaches this shall be :D
<@decathorpe:fedora.im>
15:52:49
I wonder what would actually be categorized as "Security SIG Docs"?
<@py0xc3:fedora.im>
15:52:51
No, more. But relevant here are so far Quick Docs and Security Docs. The latter is not yet decided which of the two in discussion it is :)
<@py0xc3:fedora.im>
15:53:23
I meant it not too literal. I meant Security Docs in the sense of the Security SIG reliably maintains this, its not just more Security Docs that get orphaned. We have that already in Quic kDocs :)
<@ljavorsk:fedora.im>
15:53:38
Okay so the Security Docs and Security SIG Docs are the same
<@decathorpe:fedora.im>
15:53:47
yeah. because so far I only see one thing relevant to document about the Security SIG itself - the meeting agenda / quorum thing we decided earlier
<@ljavorsk:fedora.im>
15:53:54
I was confused if these two are separete
<@ljavorsk:fedora.im>
15:54:00
I was confused if these two are separate
<@py0xc3:fedora.im>
15:54:14
Yeah, we have to decide what it means :) It's quite new.
<@rzhukov:matrix.org>
15:54:25
Does it include things like "Security policy"?
<@q5sys:matrix.org>
15:54:30
What is "Quick Docs" We have no repo for that... as far as Im aware.
<@py0xc3:fedora.im>
15:54:48
So personally, I would not put everything in Security Docs just because it has a security relation. But only what we can maintain even if one is no longer available or so.
<@decathorpe:fedora.im>
15:55:26
Maybe this is controversial, but security-related content in the Quick Docs that isn't maintained should be just dropped, and the things we *do* want to maintain can be transferred to "our" Security Docs
<@py0xc3:fedora.im>
15:55:49
+1
<@py0xc3:fedora.im>
15:56:31
But dropping anything is the Docs responsibility. Some has been dropped some time ago. But they aim to keep stuff as long as possible and emphasize more on adding times that indicate users if that might be up to date, as many no longer rely on the content anyway
<@py0xc3:fedora.im>
15:56:53
so times = timestamps
<@q5sys:matrix.org>
15:57:00
again... what is `Quick Docs`? Can anyone point me to where in the Fedora Infra that exists.
<@decathorpe:fedora.im>
15:57:03
it won't hurt to ask them to drop things that are no longer accurate
<@py0xc3:fedora.im>
15:57:08
I didn't like it, but otherwise, much of the Docs would be gone tbh :)
<@q5sys:matrix.org>
15:57:20
I have been a part of Fedora for well over a decade... I've never head of 'Quick Docs' before this meeting.
<@py0xc3:fedora.im>
15:57:23
https://docs.fedoraproject.org/en-US/quick-docs/
<@py0xc3:fedora.im>
15:57:42
Its the biggest of our Docs repos I think :)
<@decathorpe:fedora.im>
15:57:54
the sources are now here: https://forge.fedoraproject.org/docs/quick-docs
<@py0xc3:fedora.im>
15:57:56
The most used article is how to upgrade Fedora for long :D
<@salimma:fedora.im>
15:58:09
I wish in hindsight everything we have is pagure
<@salimma:fedora.im>
15:58:20
asciidoc is not actually worse but it's one more syntax to learn
<@py0xc3:fedora.im>
15:58:23
https://docs.fedoraproject.org/en-US/security/ -> not yet. It's quite new and not much contained yet
<@decathorpe:fedora.im>
15:58:57
do we actually *have* a "security policy"?
<@ljavorsk:fedora.im>
15:59:18
This will be something we would like help with
<@ljavorsk:fedora.im>
15:59:40
The Security policies are obligatory for the CRA Steward
<@q5sys:matrix.org>
15:59:41
Oh joy... another location for documentation to become stale. 🤣
<@py0xc3:fedora.im>
16:00:05
Oh yeah 😎
<@q5sys:matrix.org>
16:00:08
I have a meeting I have to step into. Someone else will need to close out this meeting.
<@py0xc3:fedora.im>
16:00:28
Yeah, we can get that done :)
<@decathorpe:fedora.im>
16:00:32
yeah, this is why I suggested to drop things **or** take responsibility for them and update them
<@py0xc3:fedora.im>
16:01:01
Shall we procrastinate this topic to next week or a ticket? Seems more to discuss than I thought
<@py0xc3:fedora.im>
16:01:13
I'm not sure we get Docs convincved :)
<@py0xc3:fedora.im>
16:01:18
But I would be +1
<@decathorpe:fedora.im>
16:01:19
we can try
<@py0xc3:fedora.im>
16:01:36
I did once, the timestamps and some deletions of "extremes" were the result.
<@decathorpe:fedora.im>
16:01:48
because I'm not sure *more* documentation is always better if it's just going to be stale or wrong ...
<@py0xc3:fedora.im>
16:01:51
But the problem is, if we radically would do that, much of the Docs just is dropped at all
<@py0xc3:fedora.im>
16:01:59
You do not need to convince me :)
<@py0xc3:fedora.im>
16:02:14
And that was the work of lobbying for over a year :)
<@decathorpe:fedora.im>
16:02:21
🤷♂️
<@decathorpe:fedora.im>
16:02:45
maybe the regulatory banhammer is a better convincing tool.
<@decathorpe:fedora.im>
16:03:04
anyway I think the timeslot for this meeting is now up?
<@decathorpe:fedora.im>
16:03:15
let's continue this discussion in #security:fedoraproject.org
<@py0xc3:fedora.im>
16:03:35
yeah, we can do. I would leave this topic for next week and discuss it in between?
<@decathorpe:fedora.im>
16:03:42
sounds good
<@decathorpe:fedora.im>
16:04:03
see you around 👋
<@decathorpe:fedora.im>
16:04:06
!endmeeting