security-sig
LOGS
<@q5sys:matrix.org>
14:59:46
!startmeeting
<@meetbot:fedora.im>
14:59:48
Meeting started at 2026-07-16 14:59:46 UTC
<@meetbot:fedora.im>
14:59:49
The Meeting name is 'Fedora Meeting 3'
<@q5sys:matrix.org>
14:59:50
!meetingname security-sig
<@meetbot:fedora.im>
14:59:51
The Meeting Name is now security-sig
<@py0xc3:fedora.im>
14:59:55
!hi
<@zodbot:fedora.im>
14:59:56
Chris (py0xc3): Christopher Klooz (py0xc3) - he / him / his
<@q5sys:matrix.org>
14:59:57
<@q5sys:matrix.org>
15:00:03
<@q5sys:matrix.org>
15:00:25
!topic Open floor to discuss anything security related. (2026-07-16)
<@q5sys:matrix.org>
15:00:29
!info Next Meeting (2026-07-23)
<@q5sys:matrix.org>
15:00:33
!info There are 8 open tickets in the main Security Forge: https://forge.fedoraproject.org/security/tickets/issues
<@q5sys:matrix.org>
15:00:36
!info There are 5 open tickets in the Security Docs Forge: https://forge.fedoraproject.org/security/docs/issues
<@q5sys:matrix.org>
15:00:40
!topic Agenda: https://discussion.fedoraproject.org/t/security-sig-meeting-agenda-for-the-meeting-on-16-07-2026/196761
<@rzhukov:matrix.org>
15:01:21
Hi folks, I have a hard stop at :30, but otherwise - looking forward to today's meeting 👍️
<@q5sys:matrix.org>
15:01:23
anyone have anything to get out there before we get into the agenda?
<@py0xc3:fedora.im>
15:01:23
Wait a moment for others to arrive and then start with 1.1?
<@salimma:fedora.im>
15:01:39
!hi
<@zodbot:fedora.im>
15:01:40
Michel Lind ☘ UTC+1 ⛱️: Michel Lind (salimma) - he / him / his
<@ljavorsk:fedora.im>
15:01:55
!hi
<@salimma:fedora.im>
15:01:55
been on vacation until yesterday so I have not seen the agenda yet, sorry
<@zodbot:fedora.im>
15:01:56
Lukas Javorsky: Lukas Javorsky (ljavorsk) - he / him / his
<@rzhukov:matrix.org>
15:02:01
!Hi folks, I have a hard stop at :30, but otherwise - looking forward to today's meeting 👍️
<@q5sys:matrix.org>
15:02:02
if rzhukov has a time limit maybe we should get to his first since he got bumped from last week
<@rzhukov:matrix.org>
15:02:12
!hi folks, I have a hard stop at :30, but otherwise - looking forward to today's meeting 👍️
<@zodbot:fedora.im>
15:02:14
Sorry, I can only look up one username at a time
<@jforbes:fedora.im>
15:02:17
!hi
<@zodbot:fedora.im>
15:02:18
jforbes: Justin Forbes (jforbes) - he / him / his
<@rzhukov:matrix.org>
15:02:32
!hi
<@zodbot:fedora.im>
15:02:34
No Fedora Accounts users have the @rzhukov:matrix.org Matrix Account defined
<@py0xc3:fedora.im>
15:02:37
1.1 is his :)
<@q5sys:matrix.org>
15:03:02
ah I was thiniking #14 which is his ticket.
<@py0xc3:fedora.im>
15:03:10
rzhukov: I think you have two topics. Which do you wanna start first?
<@rzhukov:matrix.org>
15:03:23
Let's do 1.1
<@q5sys:matrix.org>
15:03:29
sounds good, take it away
<@py0xc3:fedora.im>
15:03:30
both actually :)
<@py0xc3:fedora.im>
15:03:56
!topic 1.1. Secure development practices in Fedora
<@rzhukov:matrix.org>
15:06:00
Ok, for someone new and curious user here (like me) how can I be sure that Fedora is best-in-class in security? Does it even care?
<@jforbes:fedora.im>
15:07:43
My sleep schedule lately is proof that it cares!
<@rzhukov:matrix.org>
15:08:05
Well :) I just don't know wWe can start with the end-user perspective. Say, what I get as an end-product artifacts -
<@rzhukov:matrix.org>
15:08:40
Well :) We can start with the end-user perspective. Say, what I get as an end-product artifacts - how one can verify?
<@salimma:fedora.im>
15:09:00
I think once the new prodsec scanner is up and running we'll be in a way better shape
<@salimma:fedora.im>
15:09:11
right now I fear many maintainers ignore their CVE bugs because a lot of them are inaccurate
<@rzhukov:matrix.org>
15:10:10
I mean I can speak of nerdy SDLC terms - do we have TM, Arch Review, SAST, SCA, etc. But would rather hear what are the security practices Fedora is most proud of
<@ljavorsk:fedora.im>
15:10:12
Is something security-related part of the Package review process? I believe that is a great starting point from which a lot of security concerns could be addressed. For anyone who don't know what Package Review is: https://docs.fedoraproject.org/en-US/package-maintainers/Package_Review_Process/
<@salimma:fedora.im>
15:11:26
there are some that are security related I guess -- like ideally we want the latest version packaged (though it can be explained away), and compiler flags must be applied
<@salimma:fedora.im>
15:11:30
including the hardening one
<@py0xc3:fedora.im>
15:11:32
Building from source has a security relation. We don't have security reviews as openSuSE though. There was a project to change that some time ago as far as I remember, but I think its a lack of resources
<@salimma:fedora.im>
15:11:54
including the hardening ones
<@py0xc3:fedora.im>
15:12:41
Also, certain obligations, how to use what and when, contain security considerations
<@py0xc3:fedora.im>
15:12:52
Obligated checks, etc.
<@rzhukov:matrix.org>
15:12:58
Do you mean user guide?
<@py0xc3:fedora.im>
15:13:06
packaging
<@rzhukov:matrix.org>
15:13:09
or internal guides for dev?
<@rzhukov:matrix.org>
15:13:16
ah, for packaging, gotcha
<@jforbes:fedora.im>
15:13:20
I am not sure that people were in the Hummingbird session at Flock, but one of the things they do is AI scanning of CVEs. If there is a fix already in Fedora, they build that fix and update that package. If there is not a fix already in Fedora, they grab one from upstream, etc. Then build and push that package *and* create an MR against the package in Fedora to fix that CVE.
<@jforbes:fedora.im>
15:13:49
Now, Hummingbird is only a subset of the package list, but it is a good start, and a list of fairly critical packages
<@ljavorsk:fedora.im>
15:14:17
They create MR only for Rawhide IIRC right?
<@salimma:fedora.im>
15:14:48
* MR or PR, I assume, since apart from the kernel which uses a gitlab repo everything else is in Pagure
<@py0xc3:fedora.im>
15:15:02
forge :P
<@jforbes:fedora.im>
15:15:05
I believe so, as that is the package set they are following. Still it should at least alert a maintainer that they should check stable too
<@jforbes:fedora.im>
15:15:36
Yes, PR now against dist-git I believe. Sorry, just used to the MR terminology for kernel
<@ljavorsk:fedora.im>
15:15:38
We know how maintainers like to proactively check all stable releases :D
<@ljavorsk:fedora.im>
15:16:13
But yeah better than nothing
<@jforbes:fedora.im>
15:16:17
Yeah, but you might think if they were poked, they might at least think about it.
<@rzhukov:matrix.org>
15:17:06
https://fedoraproject.org/workstation/download/ - I like "we take security seriously"
<@jforbes:fedora.im>
15:19:12
One thing of interest, as Hummingbird catches its stride, we might be able to ask them to extend the scanner to cover all Fedora packages. Anything the automation can do would be done, and if automation can't do it (difficult backport, etc) it could at least file an issue alerting the maintainer.
<@salimma:fedora.im>
15:20:19
is this separate from the reworked CVE scanner that ProdSec is working on? if so, can the two be combined?
<@rzhukov:matrix.org>
15:20:25
So, Hummingbird is a good example of where users can actually see what exactly it means from security perspective (SLSA L3, SBOMs, all the scans that Konflux provides, etc.) - this info is available.
<@salimma:fedora.im>
15:20:34
(the ones that have been demoed at FRCL meetings, I mean)
<@ljavorsk:fedora.im>
15:21:25
Michel Lind ☘ UTC+1: which ProdSec scanner do you mean?
<@jforbes:fedora.im>
15:21:31
Hummingbird is a little different in that it doesn't care about RHEL basically so it is only looking for CVEs in new packages
<@jforbes:fedora.im>
15:21:47
Prodsec scanner needs to do a lot more work
<@rzhukov:matrix.org>
15:22:10
Is there documented coverage somewhere Hummingbird vs rest of packages?
<@salimma:fedora.im>
15:22:29
the rewritten one that is no longer doing substring matching on component names
<@salimma:fedora.im>
15:22:47
I believe someone shared the URL for the repo on github but I don't have it right in front of me
<@ljavorsk:fedora.im>
15:23:19
If you find it please send it to me
<@rzhukov:matrix.org>
15:23:32
+1
<@decathorpe:fedora.im>
15:24:18
this one? https://github.com/RedHatProductSecurity/trustshell
<@salimma:fedora.im>
15:24:37
yes
<@jforbes:fedora.im>
15:24:37
I haven't spent a lot of time looking at the Hummingbird bits, but everything they have should be public as a Fedora project. If they don't have a specific package list, one could be inferred from what they ship
<@jforbes:fedora.im>
15:25:17
https://fedoraproject.org/wiki/Hummingbird looks like a package list is linked there
<@ljavorsk:fedora.im>
15:25:38
Aaah trustshell... well, not sure if this one will be used. We had quite a lot of problems with it
<@rzhukov:matrix.org>
15:25:39
You know what, I might be asking obvious questions or otherwise things that I simply don't know yet but that exist :) So, let me rephrase - Can we (sometime offline, perhaps) go over this checklist: https://baseline.openssf.org/versions/2026-02-19-checklist.md with links/how we do it?
<@rzhukov:matrix.org>
15:29:24
Well if you run 100 scanners you will have (not 100, but ~20-30) different results... I like Konflux because it's quite modular and can allow you to include whatever scans you waould like
<@decathorpe:fedora.im>
15:29:50
looks like some of that checklist will require people actually familiar with CI/CD pipeline to chime in, because I don't think anybody outside the people working directly on that actually know
<@decathorpe:fedora.im>
15:30:21
and some look like they apply more to traditional software development, not an integration project like Fedora
<@ljavorsk:fedora.im>
15:30:29
Identifying people that work on that and action to ask them is also a great outcome
<@rzhukov:matrix.org>
15:30:45
I NTD, unfortunately, but I think what I'd suggest to do next is to try star working on this https://forge.fedoraproject.org/security/tickets/issues/14 as it's basically the list of security practices I was looking for. And OSPS ^^ (link above) as a nice comprehensive checklist
<@rzhukov:matrix.org>
15:31:16
Apologies folks, you can continue with "my" second topic or skip it - as you prefer
<@q5sys:matrix.org>
15:32:12
you said yuo had to go at :30 , do you want to bump it to next week?
<@py0xc3:fedora.im>
15:32:21
ok, we have theoretically two more topics, rzhukov 's second one, and actually not sure if there is much for the meeting concerning linux-distros?
<@py0xc3:fedora.im>
15:33:04
I think he's gone, I think it was :30 sharp for him :)
<@ljavorsk:fedora.im>
15:33:16
Bump it to next week
<@q5sys:matrix.org>
15:33:20
It feels odd to discuss someone's ticket with them not around.
<@q5sys:matrix.org>
15:33:25
so I'd prefer to bump it
<@py0xc3:fedora.im>
15:33:27
Ok, I keep it as first topic for next week then
<@py0xc3:fedora.im>
15:33:34
+1
<@py0xc3:fedora.im>
15:33:55
Needs to discuss linux-distros topic, open floor, or end?
<@q5sys:matrix.org>
15:34:37
If there's nothing to discuss for the linux-distros topic... and if no one else has anything else to bring up... we can just call the meeting here.
<@q5sys:matrix.org>
15:34:53
but if anyone has anything... by all means bring it up.
<@py0xc3:fedora.im>
15:35:33
I guess so. Just raising awareness that some discussion took place in linux distros -> https://forge.fedoraproject.org/security/tickets/issues/13
<@py0xc3:fedora.im>
15:35:33
<@py0xc3:fedora.im>
15:35:33
But I see no need to have it discussed here atm.
<@py0xc3:fedora.im>
15:35:40
(unless someone else has a point about it)
<@q5sys:matrix.org>
15:36:27
Dont wait! Call NOW! Phone lines are filling up, so hurry and secure your place... /end_infomercial_tv_advertisement 🤪
<@decathorpe:fedora.im>
15:36:39
/me realizes he hadn't "watched" this repo so didn't get any notifications
<@q5sys:matrix.org>
15:36:50
Dont wait! Call NOW! Phone lines are filling up, so hurry and secure your place... /end_late_night_infomercial_tv_advertisement 🤪
<@py0xc3:fedora.im>
15:37:46
I guess we can leave the discussion asynchronously in the ticket for now. Open floor?
<@q5sys:matrix.org>
15:38:05
open floor is fine... if anyone has anything to bring up
<@q5sys:matrix.org>
15:38:14
but its been a few min already and no one has jumped in with anything...
<@q5sys:matrix.org>
15:38:32
I figure I'll give it till :40 for someone to bring something up and if not I'll call it.
<@py0xc3:fedora.im>
15:38:36
let's make an end at :40 when no one posts till then?
<@py0xc3:fedora.im>
15:38:42
Ah, yeah, exactly :)
<@q5sys:matrix.org>
15:38:48
/queue suspense music.
<@py0xc3:fedora.im>
15:39:51
10 seconds left! last chance!
<@q5sys:matrix.org>
15:40:04
Alright, thanks everybody. Have a good rest of your week and weekend.
<@q5sys:matrix.org>
15:40:08
!endmeeting