security-sig
LOGS
<@q5sys:matrix.org>
14:59:22
!startmeeting
<@meetbot:fedora.im>
14:59:24
Meeting started at 2026-07-23 14:59:22 UTC
<@meetbot:fedora.im>
14:59:25
The Meeting name is 'Fedora Meeting 3'
<@q5sys:matrix.org>
14:59:25
!meetingname security-sig
<@meetbot:fedora.im>
14:59:27
The Meeting Name is now security-sig
<@q5sys:matrix.org>
14:59:29
<@q5sys:matrix.org>
14:59:34
<@thebeanogamer:fedora.im>
14:59:45
!hi
<@zodbot:fedora.im>
14:59:46
Daniel Milnes: Daniel Milnes (thebeanogamer) - he / him / his
<@q5sys:matrix.org>
14:59:47
!info Open floor to discuss anything security related. (2026-07-23)
<@q5sys:matrix.org>
14:59:52
!info Next Meeting (2026-07-30
<@q5sys:matrix.org>
14:59:57
!info There are 7 open tickets in the main Security Forge: https://forge.fedoraproject.org/security/tickets/issues
<@q5sys:matrix.org>
15:00:01
!info There are 6 open tickets in the Security Docs Forge: https://forge.fedoraproject.org/security/docs/issues
<@py0xc3:fedora.im>
15:00:21
!hi
<@zodbot:fedora.im>
15:00:23
Chris (py0xc3): Christopher Klooz (py0xc3) - he / him / his
<@q5sys:matrix.org>
15:00:33
!topic Agenda: https://discussion.fedoraproject.org/t/agenda-for-the-security-sig-meeting-on-23rd-july-2026/197428
<@decathorpe:fedora.im>
15:00:40
!hi
<@zodbot:fedora.im>
15:00:41
Fabio Valentini 🌈: Fabio Valentini (decathorpe) - he / him / his
<@salimma:fedora.im>
15:00:45
!hi
<@zodbot:fedora.im>
15:00:46
Michel Lind ☘ UTC+1: Michel Lind (salimma) - he / him / his
<@q5sys:matrix.org>
15:01:03
Anything critical that anyone needs to mention at the top before we jump into the first topic?
<@py0xc3:fedora.im>
15:01:13
I'm here, but on unreliable Internet. So I might disappear :D
<@mfindra:matrix.org>
15:01:31
hi
<@rzhukov:matrix.org>
15:01:35
!hi
<@zodbot:fedora.im>
15:01:38
No Fedora Accounts users have the @rzhukov:matrix.org Matrix Account defined
<@jforbes:fedora.im>
15:02:04
!hi
<@zodbot:fedora.im>
15:02:05
jforbes: Justin Forbes (jforbes) - he / him / his
<@thebeanogamer:fedora.im>
15:02:35
You'll need to set your matrix name on https://accounts.fedoraproject.org/user/rzhukov/settings/profile/
<@q5sys:matrix.org>
15:02:56
alright, nothing pressing it seems... first topic then.
<@q5sys:matrix.org>
15:02:59
!Topic #14 Review Fedora security documents to align with “Vulnerability and Incident Policy” CRA requirement https://forge.fedoraproject.org/security/tickets/issues/14
<@py0xc3:fedora.im>
15:03:22
I think topic needs to be lower case (?)
<@q5sys:matrix.org>
15:03:45
!topic #14 Review Fedora security documents to align with “Vulnerability and Incident Policy” CRA requirement https://forge.fedoraproject.org/security/tickets/issues/14
<@rzhukov:matrix.org>
15:03:52
!hi
<@zodbot:fedora.im>
15:03:55
rzhukov: Roman Zhukov (rzhukov)
<@thebeanogamer:fedora.im>
15:04:57
So on this one I'd really like a steer from rzhukov. We _can_ try and plow through everything mentioned on that ticket, but some idea of priority would be nice
<@rzhukov:matrix.org>
15:05:24
Sec, typing
<@rzhukov:matrix.org>
15:06:34
This ticket ^^ started with simple Review existing docs against the Stewardship guidelines (see this first line item https://access.redhat.com/security/eu-cyber-resilience-act-stewardship-guidelines#:~:text=Cybersecurity%2C%20Vulnerability%20Management%20and%20Incident%20Response%20Policy)
<@rzhukov:matrix.org>
15:06:57
But I like how discussion involved into actually making a table
<@rzhukov:matrix.org>
15:07:12
with the entire lists of guidelines and doing gap analysysy
<@rzhukov:matrix.org>
15:07:51
So, I'd suggest step-by-step:
<@rzhukov:matrix.org>
15:08:33
1) For this ticket - do the docs gap analysys. I saw someone mentioned that infra, docs, other teams may be involved. So, would be looking for volunteer who can go ahead and investigate :)
<@rzhukov:matrix.org>
15:09:28
2. Create an artifact (e.g. .md) in one of the repos with the full table of Guidelines. If someone can point me out to the repo - I can make an initial MR
<@rzhukov:matrix.org>
15:09:35
wdyt?
<@thebeanogamer:fedora.im>
15:10:38
Do you mean create a document so we can collaborate on each point, or create a doc in the docs site that'll link to what we do on each point
<@rzhukov:matrix.org>
15:11:29
for #1 - I mean take the 6 items: 1) Secure development practices 2) Contact information for security questions, vulnerabilities and incidents reporting 3) Contact information of the project’s Steward (cra-steward@redhat.com) 4) The processes for vulnerability reporting, identification, remediation, patching, and coordinated disclosure (CVD). 5) The process for handling incidents for underlying infrastructure and tooling used 6) Intended support period for addressing vulnerabilities and the end-of-life process.
<@rzhukov:matrix.org>
15:11:54
and map them to existing Fedora docs. Where does not exist - suggest which doc will be the best to amend
<@rzhukov:matrix.org>
15:13:16
For #2 - let start with the targeted repo where I can push an .md file with what I think would be a good tracking table so that we go over, do gap analysys and create issues for missing items
<@q5sys:matrix.org>
15:13:33
`map them to existing Fedora docs` I think some of those will just need to be created entlrey. If anything exists, it's probably going to be very outdated (on an old wiki or something no one bothers with anymore).
<@q5sys:matrix.org>
15:14:12
stale info has been a problem for years, and there's no easy fix since things are scattered around a half a dozen locations.
<@salimma:fedora.im>
15:14:53
RH is the CRA steward by default because there is no standalone Fedora legal entity, I assume?
<@q5sys:matrix.org>
15:14:54
What might be better long term... is to just decide as a team where we want the current info to reside... and focus on creating/improving what exists and create a single source of truth for 'current' cocs.
<@rzhukov:matrix.org>
15:15:15
ah, ok. then in this ticket (https://forge.fedoraproject.org/security/tickets/issues/14) we can propose what we think is the good approach for each of those 6 items
<@salimma:fedora.im>
15:15:26
or would it make sense to have a fedoraproject.org alias, even though right now it just forwards to the RH address?
<@py0xc3:fedora.im>
15:15:41
I think there is a council ticket about this. It is not obligated but encouraged.
<@rzhukov:matrix.org>
15:16:09
RH is the Steward for Fedora by current (veg) definition in the CRA and our understanding.
<@thebeanogamer:fedora.im>
15:16:28
Seems like a reasonable starting point
<@rzhukov:matrix.org>
15:17:03
If someone can lead the charter, I'm of course happy to contribute/help/etc.
<@py0xc3:fedora.im>
15:17:24
https://forge.fedoraproject.org/council/tickets/issues/559
<@salimma:fedora.im>
15:17:26
"veg" ?
<@rzhukov:matrix.org>
15:19:14
Yes, because there are many interpretations who can, can not be and must be Steward and for what. Even within EU Comm there are different opinions. But I personally think it doesn't prevent us from doing reasonable things/improvements
<@rzhukov:matrix.org>
15:19:47
Moving on, I'll be willing to accept more support and contributions from other companies. We in fact discussed that already already at Flock with AWS and MS
<@salimma:fedora.im>
15:20:13
ah, sorry , I meant I am not sure what 'veg' means
<@rzhukov:matrix.org>
15:20:31
So far, we consider Red Hat as a "leading" Steward anyway :) Until somebody tells us the opposite...
<@rzhukov:matrix.org>
15:20:57
Ah, sure. Sorry. Veg = nobody really understands what it means xD
<@q5sys:matrix.org>
15:21:28
veg = vague?
<@rzhukov:matrix.org>
15:21:51
pretty much
<@py0xc3:fedora.im>
15:22:07
I'm not sure if I like that we forward people in docs to RH without making clear for what. It remains very implicit. (Concerning the above comment to add "contact details of the steward").
<@thebeanogamer:fedora.im>
15:22:46
Right but in reality, Fedora and Red Hat are so tightly intertwined that this isn't the place to start with unpicking that
<@py0xc3:fedora.im>
15:23:00
Yeah, good point too
<@rzhukov:matrix.org>
15:23:02
1 sec. Here is our security.md template and what we suggest to include into the docs:
<@salimma:fedora.im>
15:23:17
yeah, that's why I was wondering if future-proofing by making that a new Fedora email would help. it does not matter right now, it might matter in the future
<@q5sys:matrix.org>
15:23:18
Where's your spirit of adventure? 🤣
<@rzhukov:matrix.org>
15:23:40
https://github.com/RedHatProductSecurity/CRA/blob/main/Templates/Security_MD_template.md
<@rzhukov:matrix.org>
15:23:53
So, this disclaimer is good enough to add:
<@rzhukov:matrix.org>
15:23:54
This project is stewarded by Red Hat, Inc., an open source software steward as defined in Article 3(14) of the EU Cyber Resilience Act (Regulation 2024/2847). Contact: cra-steward@redhat.com
<@rzhukov:matrix.org>
15:23:54
Refer to Red Hat's security practices and vulnerability management policy for detailed information.
<@rzhukov:matrix.org>
15:23:54
<@rzhukov:matrix.org>
15:23:54
EU Cyber Resilience Act — Open Source Steward Statement
<@rzhukov:matrix.org>
15:24:10
This project is stewarded by Red Hat, Inc., an open source software steward as defined in Article 3(14) of the EU Cyber Resilience Act (Regulation 2024/2847). Contact: cra-steward@redhat.com
<@rzhukov:matrix.org>
15:24:10
<@rzhukov:matrix.org>
15:24:10
EU Cyber Resilience Act — Open Source Steward Statement
<@py0xc3:fedora.im>
15:24:20
+1 to that. I think getting one as forwarding shouldn't be hard
<@rzhukov:matrix.org>
15:25:06
So, it's to notify others (just in case) to direct all "legalish" questions to Red Hat, not to community. While we should keep actual "real" security docs and processes in Fedora.
<@decathorpe:fedora.im>
15:25:57
so ... into *which* docs?
<@thebeanogamer:fedora.im>
15:26:02
This seems like a good starting point. The exact destination for those reports feels like it leads into the second topic for this meeting (where do reports from the linux-distros list go)
<@thebeanogamer:fedora.im>
15:26:12
Security, surely?
<@jforbes:fedora.im>
15:26:14
I mean until we get a Fedora Legal SIG :)
<@q5sys:matrix.org>
15:26:19
that question just keeps coming around doesn't it?
<@decathorpe:fedora.im>
15:26:42
so ... forge/security/docs ? :)
<@decathorpe:fedora.im>
15:26:42
I mean, I agree, just Security docs
<@thebeanogamer:fedora.im>
15:27:06
That's where I'd put it
<@q5sys:matrix.org>
15:27:16
I would say for the mean time... we just start using https://forge.fedoraproject.org/security/docs If we come up with a better idea in the future we can move them later.
<@q5sys:matrix.org>
15:27:43
no point holding up writing things due to going round and round about where to save them.
<@mfindra:matrix.org>
15:27:47
https://forge.stg.fedoraproject.org/Rainbows-and-Unicorns/issue_creation_test/src/branch/main/security.md
<@py0xc3:fedora.im>
15:28:01
There will be in the end two docs. One about the team in the team docs, one about security topics. The latter might get its own badge on the main page. I like the idea Daniel Milnes added earlier about how to distinguish them, as that might be realistic to keep on the long term and still not destroying SEO.
<@py0xc3:fedora.im>
15:28:29
Though not sure if that is already relevant at this stage (?)
<@mfindra:matrix.org>
15:28:36
security.md example from thrcka
<@thebeanogamer:fedora.im>
15:28:46
Strong plus one
<@salimma:fedora.im>
15:30:24
yeah, we can move things later, let's just not make perfect be the enemy of good
<@salimma:fedora.im>
15:30:42
'where to put things' is really hard to figure out *until* things are writtten anyway, because right now we have only vague ideas
<@thebeanogamer:fedora.im>
15:31:13
So the only thing we really need to answer then is "Where do the reports go"
<@thebeanogamer:fedora.im>
15:31:25
To which I'm tempted to say "Bugzilla email, similar to the linux-distros one"
<@py0xc3:fedora.im>
15:31:55
Docs-authoring teams once managed to get Fedora out of every search engine first page even for most search queries involving the term Fedora Linux. At the same time, pages were undiscovereable even by the docs team when asked despite them being embedded in the community. My point is not that it is wrong what we do now, but just "hey writing and publishing is always good" is not always the case. It's more complex than that ;)
<@decathorpe:fedora.im>
15:32:10
private mailing list should be an OK temporary solution, until we have private tickets in forgejo.
<@q5sys:matrix.org>
15:32:16
trying to look at it as a lay person... it would seem people would think they would create them under 'tickets' based on the wording of the two repos.
<@decathorpe:fedora.im>
15:32:34
though somebody will need to deal with spam moderation on that list.
<@salimma:fedora.im>
15:32:36
I missed RHCL yesterday due to a scheduling snafu, I wonder if they did talk about bugzilla or not.
<@salimma:fedora.im>
15:32:49
I wanted to flag that hey the Security SIG is now using it in lieu of any better place for embargoed discussions
<@decathorpe:fedora.im>
15:32:49
shouldn't have - bugzilla topic is scheduled for later.
<@py0xc3:fedora.im>
15:33:04
100%
<@salimma:fedora.im>
15:33:06
ah ok, so it was really open discussions, I thought initially that was next week
<@thebeanogamer:fedora.im>
15:33:11
I think this is the same as the linux-distros reports though in that we need somewhere private and Forgejo can't do that toda
<@decathorpe:fedora.im>
15:33:14
yes, but that doesn't support private tickets (for security reports) yet.
<@thebeanogamer:fedora.im>
15:33:14
I think this is the same as the linux-distros reports though in that we need somewhere private and Forgejo can't do that today
<@thebeanogamer:fedora.im>
15:33:39
So yeah Bugzilla or mailing list, and personally I'm a sucker for a good ticketing platform
<@q5sys:matrix.org>
15:33:58
Does forge allow templates? We could make the first line of filing a ticket be a warning about no private tickets.
<@q5sys:matrix.org>
15:34:07
Does forge allow issue templates? We could make the first line of filing a ticket be a warning about no private tickets.
<@thebeanogamer:fedora.im>
15:34:10
Indeed it does
<@decathorpe:fedora.im>
15:34:41
yup
<@rzhukov:matrix.org>
15:35:04
Question: do you wanna go with reviewing/amending existing Fedora docs (listed https://forge.fedoraproject.org/security/tickets/issues/14) having 6 guidelines items in mind OR do you want to start something from scratch from those 6 guideline items (e.g. 1) Unified Vulnerability and Incident Policy; 2) Secure Dev Practices; .....)?
<@thebeanogamer:fedora.im>
15:35:57
Don't think Forgejo supports sub-tasks, so I'd be tempted to say ticket per item
<@thebeanogamer:fedora.im>
15:36:02
So they can be worked on seperately
<@thebeanogamer:fedora.im>
15:36:06
But maybe I've spent too long on Jira
<@decathorpe:fedora.im>
15:36:07
I'm pretty sure they'll all be "we need to write this from scratch" anyway so yeah
<@q5sys:matrix.org>
15:36:10
Even if we do plan to direct people to bugzilla, we should still put something in place in the tickets docs for people that end up doing a drive-by because they didn't see where they should go.
<@thebeanogamer:fedora.im>
15:36:33
I think you can also have an issue template that's actually a link, so that can funnel people to the right page
<@rzhukov:matrix.org>
15:37:00
(I have "voice/video" meetings all day, but this text one is something stand out - I need a break after it indeed 🤣)
<@decathorpe:fedora.im>
15:37:21
yeah ...
<@decathorpe:fedora.im>
15:37:36
so what I'm kind of missing is what are the actual action items now?
<@q5sys:matrix.org>
15:37:45
but we dont want to direct ALL tickets to a link. haha
<@py0xc3:fedora.im>
15:37:54
The sacrifice for transparency and discoverability, but yes, I know what you mean :)
<@q5sys:matrix.org>
15:37:59
but we dont want to direct ALL tickets to a link. haha so we'll probably need a few templates
<@salimma:fedora.im>
15:39:04
I generally find text meetings easier to deal with, but yeah, I wonder if some of these questions could probably be dealt better async
<@thebeanogamer:fedora.im>
15:39:18
* Create a Forgejo ticket for each of the 6 items
<@thebeanogamer:fedora.im>
15:39:18
* Close #14 as complete
<@thebeanogamer:fedora.im>
15:39:18
In my eyes:
<@thebeanogamer:fedora.im>
15:39:18
* Draft PR for the docs site with that SECURITY.md
<@thebeanogamer:fedora.im>
15:39:18
* Create a new list/bugzilla component for security vulnerability reports
<@salimma:fedora.im>
15:39:24
in tickets, that is
<@decathorpe:fedora.im>
15:40:05
yeah that sounds very sensible
<@decathorpe:fedora.im>
15:40:29
need to pandoc -i SECURITY.md -o SECURITY.adoc .... because ✨️ antora ✨️
<@thebeanogamer:fedora.im>
15:40:42
I was going to do it by hand, that's way too sensible
<@rzhukov:matrix.org>
15:41:12
(text meeting are tolls for non-native English speaker, but anyway...)
<@decathorpe:fedora.im>
15:41:14
I mean you do you but I can for the life of me not commit asciidoc syntax to my head
<@decathorpe:fedora.im>
15:41:34
oh yeah. it's sometimes difficult for me as a German native speaker too ...
<@thebeanogamer:fedora.im>
15:41:44
Intellij has a lint rule for "You've written markdown syntax in an asciidoc file" and I rely on it heavily
<@rzhukov:matrix.org>
15:42:39
Let me see if I get it. You want to create 1 Security.md file to include all 6 items into it OR create 6 (or maybe less) news doc incorporating those items OR both of those actions?
<@decathorpe:fedora.im>
15:43:18
that probably depends on how much content there will be for each of those points? if it's just one sentence, then separate documents doesn't make much sense to me IMO
<@salimma:fedora.im>
15:43:38
fair, funnily most of us are likely non native speakers here? I know I'm not. On FESCo it's probably majority non native speakers too
<@q5sys:matrix.org>
15:43:54
although its easier to translate text afterwords rather than a video recording
<@salimma:fedora.im>
15:44:38
right, "AI transcriptions" are also not friendly to non-native speakers
<@salimma:fedora.im>
15:45:22
but anyway... let's not derail before I go into a spiel about how horrible it is to see a lot of blurry faces in a meeting room across VC and not knowing who any of the speakers are
<@rzhukov:matrix.org>
15:45:54
(I'd agree, but my transcript parser using locally hosted model does a pretty good job actually for most of the time from the audio stream. Not to mention if you enable native captions recording in the video call itself)
<@rzhukov:matrix.org>
15:48:08
that's the main point. I'd suggest the docs are not "formal" docs, but actually helpful. That's why I'm suggesting these different options - we may reuse existing docs, but if there is no "appetite" to go with full review, perhaps a few sentences into 1 single .md file would be perfect. We would need short and concise security.md files anyway to push to repos
<@thebeanogamer:fedora.im>
15:48:49
Have you got any other projects which have adopted that template, so we can get a feel for what should go in the placeholders?
<@rzhukov:matrix.org>
15:49:01
security.md = minimal info how to report, contacts, etc. Actual docs = elaboration on the full process, practices, etc.
<@rzhukov:matrix.org>
15:49:07
Sure, sec
<@rzhukov:matrix.org>
15:49:34
Actually, have a look at the table https://access.redhat.com/security/eu-cyber-resilience-act-stewardship-guidelines#:~:text=Cybersecurity%2C%20Vulnerability%20Management%20and%20Incident%20Response%20Policy
<@rzhukov:matrix.org>
15:49:54
there are links in the third column to those examples.
<@decathorpe:fedora.im>
15:50:03
or would this need to go into *every* dist-git repo too?
<@decathorpe:fedora.im>
15:50:03
<@decathorpe:fedora.im>
15:50:03
<@decathorpe:fedora.im>
15:50:03
so which repos would we be talking about here?
<@decathorpe:fedora.im>
15:50:03
> We would need short and concise security.md files anyway to push to repos
<@decathorpe:fedora.im>
15:50:03
stuff hosted on forge.fedoraproject.org?
<@rzhukov:matrix.org>
15:50:16
But if you're asking for "Red Hatty" one - here it is: https://github.com/stackrox/stackrox?tab=security-ov-file
<@thebeanogamer:fedora.im>
15:50:24
Ah cool, based on https://github.com/uxlfoundation/oneDNN?tab=security-ov-file I think we could get the simple version into one doc and link out to bigger ones as requeed
<@thebeanogamer:fedora.im>
15:50:48
I think you could put this on the docs site, in the same way we don't have a LICENSE.md in every repo
<@rzhukov:matrix.org>
15:50:56
I don't think it'd go to every repo, to be honest. If we can identify "the core" it'd be great.
<@rzhukov:matrix.org>
15:51:58
The main point in short security.md files is discoverability. People (and now agents) kind of expected to find these artifacts to report about vuln
<@thebeanogamer:fedora.im>
15:52:45
I've had a backlog item to put a security.txt on the public sites
<@thebeanogamer:fedora.im>
15:52:59
So that could point at the docs with the security.md
<@thebeanogamer:fedora.im>
15:53:08
Maybe also a link directly to it on the main site
<@decathorpe:fedora.im>
15:55:06
anyway I have another meeting in 5 minutes, gotta go
<@rzhukov:matrix.org>
15:55:11
(not that I have a huge vote here 🤣) I agree with all actions, but the first one. May I suggest to not close this ticket yet, but instead propose/write how these new/rewritten policy docs may look like? Or create a new ticket for this work item :)
<@thebeanogamer:fedora.im>
15:55:42
Sure, let's use the current one to document a plan
<@q5sys:matrix.org>
15:56:28
The current ticket is probably the best place to continue to discuss it.
<@q5sys:matrix.org>
15:56:50
I dont think we'll resolve everything in the next 3 minutes. haha
<@thebeanogamer:fedora.im>
15:57:24
Yeah maybe let's leave it there rather than trying to cram in the other topic
<@thebeanogamer:fedora.im>
15:57:33
And we can fan the actions out on Forge
<@rzhukov:matrix.org>
15:57:39
And for other items (beyond policy) - we can create another ticket or repo with a table/gap anal
<@jforbes:fedora.im>
15:57:43
Sounds reasonable
<@q5sys:matrix.org>
15:57:55
yea we'll bump Linux-distros discussion | https://forge.fedoraproject.org/security/tickets/issues/13 to the top of the next meeting, if there's time next week we can return to this topic to discuss ideas over this past week.
<@rzhukov:matrix.org>
15:57:59
sounds great, thanks folks, have a good one!
<@salimma:fedora.im>
15:58:31
thanks all!
<@py0xc3:fedora.im>
15:58:44
Do we need that? I left it because I wasn't sure if people want to discuss it, given the attention it got.
<@q5sys:matrix.org>
15:58:48
Have a great rest of your week and relaxing weekend.
<@py0xc3:fedora.im>
15:59:02
But it doesn't hurt, so either way fine I guess
<@q5sys:matrix.org>
15:59:10
we can at least see if there's further comment, if not, we can move on.
<@py0xc3:fedora.im>
15:59:39
Yeah makes sense
<@py0xc3:fedora.im>
15:59:45
See you around, thanks everybody :)
<@q5sys:matrix.org>
15:59:54
!endmeeting