security-sig
LOGS
<@py0xc3:fedora.im>
15:00:21
!startmeeting
<@meetbot:fedora.im>
15:00:22
Meeting started at 2026-07-30 15:00:21 UTC
<@meetbot:fedora.im>
15:00:22
The Meeting name is 'Fedora Meeting 3'
<@py0xc3:fedora.im>
15:00:28
!meetingname security-sig
<@meetbot:fedora.im>
15:00:28
The Meeting Name is now security-sig
<@py0xc3:fedora.im>
15:00:32
!hi
<@zodbot:fedora.im>
15:00:33
Chris (py0xc3): Christopher Klooz (py0xc3) - he / him / his
<@salimma:fedora.im>
15:00:37
!hi
<@py0xc3:fedora.im>
15:00:38
<@py0xc3:fedora.im>
15:00:44
<@py0xc3:fedora.im>
15:00:47
!info Next Meeting (2026-08-06)
<@py0xc3:fedora.im>
15:00:52
!topic Agenda: https://discussion.fedoraproject.org/t/security-sig-meeting-agenda-for-the-meeting-on-30th-july-2026/197942
<@py0xc3:fedora.im>
15:01:01
If anyone has an urgent point or announcement that should precede the agenda topics, feel free to let us know. Otherwise I would wait a moment for everyone to arrive and then start.
<@thebeanogamer:fedora.im>
15:01:09
!hi
<@py0xc3:fedora.im>
15:01:12
Due to participants' schedules, we shift the 2.1. CNA issue to the first place of the agenda
<@mfindra:matrix.org>
15:01:15
!hi
<@decathorpe:fedora.im>
15:01:20
!hi
<@zodbot:fedora.im>
15:01:21
No Fedora Accounts users have the @mfindra:matrix.org Matrix Account defined
<@ljavorsk:fedora.im>
15:01:22
!hi
<@zodbot:fedora.im>
15:01:24
Fabio Valentini 🌈: Fabio Valentini (decathorpe) - he / him / his
<@zodbot:fedora.im>
15:01:25
Lukas Javorsky: Lukas Javorsky (ljavorsk) - he / him / his
<@thebeanogamer:fedora.im>
15:01:43
!hi
<@salimma:fedora.im>
15:01:46
Michal Findrawant to register your matrix account in accounts.fedoraproject.org ?
<@thebeanogamer:fedora.im>
15:01:50
(Zodbot did I do something to offend you?)
<@py0xc3:fedora.im>
15:02:12
!topic 2.1. Fedora is CNA since 2019, currently integrated into Red Hat ProdSec
<@py0xc3:fedora.im>
15:02:16
<@salimma:fedora.im>
15:02:20
poor zodbot has been having a bad time this week
<@mfindra:matrix.org>
15:02:22
sure
<@mfindra:matrix.org>
15:02:37
I thought I did it already
<@thebeanogamer:fedora.im>
15:02:52
So yeah, didn't know this was a thing
<@thebeanogamer:fedora.im>
15:03:00
Would be nice to document what we currently have
<@salimma:fedora.im>
15:03:12
iirc if it's not a Fedora.im account you need to use that funny Matrix syntax
<@decathorpe:fedora.im>
15:03:17
just to clarify - did *anybody* on the Fedora side of the firewall know about this?
<@salimma:fedora.im>
15:03:18
@ user : domain
<@salimma:fedora.im>
15:03:27
not me
<@salimma:fedora.im>
15:03:34
IIRC Neal said he knows
<@salimma:fedora.im>
15:03:48
but he thought it was only meant for internal fedora infra stuff
<@decathorpe:fedora.im>
15:03:51
doesn't count πŸ˜†
<@thebeanogamer:fedora.im>
15:04:28
Which would make sense, but the links on the CVE site just go to all the security bugs in Bohdi
<@decathorpe:fedora.im>
15:06:34
yeah looks like there's definitely some things that don't line up
<@jforbes:fedora.im>
15:07:01
Fedora as a CNA is limited in what it can do
<@ljavorsk:fedora.im>
15:07:21
Looks like there are some CVEs reported under Fedora CNA, e.g.: https://www.cve.org/CVERecord?id=CVE-2025-10256
<@thebeanogamer:fedora.im>
15:07:56
Don't suppose someone Red Hat-ey can see who filed that one?
<@mfindra:matrix.org>
15:07:57
I reserved 2 CVEs today using Fedora pool
<@jforbes:fedora.im>
15:07:59
Essentially it is meant to apply to places where Fedora is the upstream or has diverged from upstream in a meaninful way to where the CVE would only apply to Fedora and its downstreams
<@mfindra:matrix.org>
15:08:11
I can see who did that
<@mfindra:matrix.org>
15:08:15
one sec
<@conan_kudo:matrix.org>
15:08:42
!hi
<@mfindra:matrix.org>
15:08:43
β”œβ”€ Reserved by: trathi@redhat.com (fedora)
<@mfindra:matrix.org>
15:08:43
β”œβ”€ Reserved on: Thu Sep 11 06:11:12 2025 +0000
<@mfindra:matrix.org>
15:08:43
CVE-2025-10256
<@mfindra:matrix.org>
15:08:43
└─ Updated on: Wed Feb 18 20:26:46 2026 +0000
<@mfindra:matrix.org>
15:08:43
β”œβ”€ State: PUBLISHED
<@mfindra:matrix.org>
15:08:43
β”œβ”€ Owning CNA: fedora
<@decathorpe:fedora.im>
15:08:48
I'm wondering whether saying that this CNA is "Fedora" actually violates trademark rules if it's not been signed off by Council?
<@zodbot:fedora.im>
15:08:49
Conan Kudo 😌: Neal Gompa (ngompa) - he / him / his
<@ljavorsk:fedora.im>
15:09:12
Yeah so probably Red Hat Prodsec team is using this pool only
<@conan_kudo:matrix.org>
15:09:21
AFAIK it's based on our LANANA name, so it should be fine
<@salimma:fedora.im>
15:09:26
council sign off on trademark seems very vibe-y
<@conan_kudo:matrix.org>
15:09:27
that was previously authorized by the Fedora Board
<@ljavorsk:fedora.im>
15:09:29
Yeah so probably only Red Hat Prodsec team is using this pool
<@thebeanogamer:fedora.im>
15:09:38
What's the division on that vs using Red Hat's own CNA?
<@conan_kudo:matrix.org>
15:10:13
but we probably should figure out how fedora itself can manage its CNA
<@ljavorsk:fedora.im>
15:10:14
I would say CVEs that don't affect Red Hat products, but do affect Fedora
<@mfindra:matrix.org>
15:10:31
correct
<@conan_kudo:matrix.org>
15:10:41
that's probably not a workable distinction
<@conan_kudo:matrix.org>
15:11:09
not without qualifiers about the currency of effect
<@conan_kudo:matrix.org>
15:11:23
e.g. ipsilon was in RHEL and now isn't, but still is in older RHEL
<@conan_kudo:matrix.org>
15:11:26
so now what?
<@mfindra:matrix.org>
15:11:39
shipped in rhel - rhel pool
<@mfindra:matrix.org>
15:11:55
not rhel red hat
<@salimma:fedora.im>
15:12:00
ok what if it's shipped in fedora and rhel
<@mfindra:matrix.org>
15:12:07
not rhel - red hat pool
<@salimma:fedora.im>
15:12:13
say the old version in rhel is affected and the new version in fedora is also affected
<@ljavorsk:fedora.im>
15:12:19
Then RHEL pool
<@mfindra:matrix.org>
15:12:21
if both - red hat pool
<@salimma:fedora.im>
15:12:43
makes the upstream/downstream distinction a bit flipped on its head but sure, I can live with that
<@ljavorsk:fedora.im>
15:12:46
/s/RHEL/Red Hat
<@salimma:fedora.im>
15:12:47
though it probably should be documented
<@mfindra:matrix.org>
15:12:50
if not shipped in any -> CNA LR (Last resort )
<@thebeanogamer:fedora.im>
15:12:53
My ideal end state for this discussion is a short page in the security docs that says: we have this, these people (ideally a FAS group) can use it, these are the times when it should be used, and how to issue one. If the last point is just a link to the Red hat careers site for now then fine
<@thebeanogamer:fedora.im>
15:13:01
But as Neal says, ideall Fedora runs this
<@thebeanogamer:fedora.im>
15:13:04
But as Neal says, ideally Fedora runs this
<@decathorpe:fedora.im>
15:13:38
sounds like this wood be a good candidate of a page to add to the security docs!
<@conan_kudo:matrix.org>
15:14:35
especially as we start actively participating in embargoed discussions and things of that nature, we as fedora produce plenty of things as the "true upstream" and it makes sense to figure out how to manage it as the CNA for that purpose
<@ljavorsk:fedora.im>
15:14:45
But since Red Hat does full VM for Fedora, how do they (someone from Fedora community) knows what security bugs should reserve a CVE in Fedora pool?
<@conan_kudo:matrix.org>
15:14:56
like, it would be silly if Red Hat was the CNA for a vulnerability in rpm macros that Red Hat doesn't participate in at all except for shipping it
<@mfindra:matrix.org>
15:15:45
also the rule still is that we only reserve CVEs for components that are not under other CNA
<@conan_kudo:matrix.org>
15:15:47
especially if the upstream is a Fedora developer that doesn't work for Red Hat
<@salimma:fedora.im>
15:15:53
yeah, I think those closer to where the software is developed should own it
<@mfindra:matrix.org>
15:16:03
eg. kernel - we never reserve CVEs for kernel
<@salimma:fedora.im>
15:16:08
and until we adopt PURL the security vulnerability assignment in Fedora is a bit of a crapshoot anyway
<@conan_kudo:matrix.org>
15:16:30
how does PURL help us?
<@salimma:fedora.im>
15:16:52
we should probably document a few things right? a) what we have - b) how we think we can use it today, c) the ideal end state and how to get there
<@conan_kudo:matrix.org>
15:17:01
yeah
<@salimma:fedora.im>
15:17:03
Conan Kudo 😌it stops bugs being assigned against the wrong component by substring search
<@py0xc3:fedora.im>
15:17:08
Yes, documentation is the biggest issue I see at the moment.
<@py0xc3:fedora.im>
15:17:17
that's where it should start imho
<@conan_kudo:matrix.org>
15:17:17
ah right that
<@ljavorsk:fedora.im>
15:17:24
Yeah it's not documented at all so to speak :D
<@py0xc3:fedora.im>
15:17:45
then we can see what to make of it and how to develop and align things. But first we need something clear that can be aligned :)
<@py0xc3:fedora.im>
15:18:03
Not sure that can be resolved within a meeting before (?)
<@thebeanogamer:fedora.im>
15:18:06
In the hopes of moving towards an action item, Lukas Javorsky Michal Findra would one of you be willing to write the page for https://forge.fedoraproject.org/security/docs/ documenting how it works today, then we can figure out what tomorrow looks like
<@ljavorsk:fedora.im>
15:19:40
Michal Findra: has more hands-on experience on this so I would leave it to him if that's okay Michal. Either way we'll have a sync on it so if there is something I can help with I'm willing
<@py0xc3:fedora.im>
15:20:44
!action Michal Findra to start drafting a related page for https://forge.fedoraproject.org/security/docs/
<@py0xc3:fedora.im>
15:20:54
If there is anything we can help with concerning Docs or so, feel free to let us know
<@py0xc3:fedora.im>
15:21:34
More about this topic?
<@ljavorsk:fedora.im>
15:22:13
Chris (py0xc3): you have some specific module(space) you want the doc to be drafted?
<@ljavorsk:fedora.im>
15:22:33
Or should a new dir be created in https://forge.fedoraproject.org/security/docs/src/branch/main/modules/ROOT/pages
<@py0xc3:fedora.im>
15:22:33
you can still use the default module, ROOT. for the team docs and stuff like that, this will not change.
<@decathorpe:fedora.im>
15:23:29
modules/ROOT/pages/CNA.adoc or something like that should be fine
<@py0xc3:fedora.im>
15:23:52
exactly
<@py0xc3:fedora.im>
15:24:23
We can then see how to put it best to the nav.adoc. I don't have the current sub categories in mind off the cuff tbh :)
<@decathorpe:fedora.im>
15:24:34
([FESCo docs](https://forge.fedoraproject.org/fesco/docs/src/branch/main/fesco/modules/ROOT/pages) are also just a flat directory structure like this, the actual docs structure is in `nav.adoc`)
<@py0xc3:fedora.im>
15:24:56
I think to have seen there is a sub category for cryptography. But not sure off the cuff
<@py0xc3:fedora.im>
15:25:15
Anyway, in case of a doubt, we can just leave it at the main category without a sub or so
<@py0xc3:fedora.im>
15:25:26
We don't have that much anyway :)
<@ljavorsk:fedora.im>
15:25:49
We'll need to leave shortly, is there anything else CNA related you wanted to ask?
<@decathorpe:fedora.im>
15:26:15
I think that covers things for now :)
<@py0xc3:fedora.im>
15:26:31
Shall I move on with topics?
<@py0xc3:fedora.im>
15:26:41
!topic 1.1. #13 Linux-distros discussion
<@decathorpe:fedora.im>
15:26:45
THOU SHALL
<@py0xc3:fedora.im>
15:26:45
<@py0xc3:fedora.im>
15:27:25
I think there is not much new on the Linux-distros discussion. One might add that @jforbes mentioned that co-maintainers for the kernel are ramping up, which is great news with (positive) security implications on the long term. When the linux-distros discussion is more advanced and the roles/expectations better defined, we might ask if they should be considered for the second member at the mailing list (if we get two). But I think that's nothing to discuss at this stage. Anyone else anything to add to this topic?
<@salimma:fedora.im>
15:28:00
I've been a bit busy, what's the blocker on getting this working right now?
<@jforbes:fedora.im>
15:28:01
I would say not at this point
<@salimma:fedora.im>
15:28:16
like, what are we waiting for before asking for this in oss-sec
<@decathorpe:fedora.im>
15:28:43
I would like to avoid hardcoding anything into policy that relies on bugzilla, with its sunset date being on the horizon (EOY plusminus a few months?)
<@py0xc3:fedora.im>
15:29:34
Well, the process is one thing. I suggested something that can be "questioned". Not sure that is ready for approval.
<@jforbes:fedora.im>
15:29:44
I don't think bugzilla is a requirement, any replacement should (according to the flock discussion) support private tickets
<@thebeanogamer:fedora.im>
15:29:47
We can probably keep the implantation , but we do need somewhere private
<@thebeanogamer:fedora.im>
15:29:59
We can probably keep the implantation vague, but we do need somewhere private
<@py0xc3:fedora.im>
15:30:18
Yes, indeed. Not sure I considered that yet. One thing to review+change if applicable
<@salimma:fedora.im>
15:30:20
jforbesI think we should plan for the worst case scenario though
<@py0xc3:fedora.im>
15:30:25
If that draft is useful at all to eveerybody
<@decathorpe:fedora.im>
15:30:36
bugzilla should be fine until forge.fp.o supports private tickets, hopefully the latter happens before the former is shut fown.
<@decathorpe:fedora.im>
15:30:40
bugzilla should be fine until forge.fp.o supports private tickets, hopefully the latter happens before the former is shut down.
<@salimma:fedora.im>
15:30:46
e.g. pagure.io usage of private tickets... is now gone on forge.fp.o even though private tickets are not supported yet
<@salimma:fedora.im>
15:31:00
so yeah, hopefully the next sunset works better but we should not assume it will
<@conan_kudo:matrix.org>
15:31:06
I'm not particularly confident on a timeline for forge.fp.o supporting private tickets
<@conan_kudo:matrix.org>
15:31:15
so we should think about alternatives to that
<@decathorpe:fedora.im>
15:31:21
me either, hence my "hopefully"
<@decathorpe:fedora.im>
15:31:35
though I have seen progress on those feature branches recently.
<@py0xc3:fedora.im>
15:31:45
I also don't like to have this outside of Fedora, but the possibility with freedesktop.org remains. We depend on them indirectly anyway. It might be also considered as worst case back up, if we want to have one.
<@thebeanogamer:fedora.im>
15:32:35
I’m not convinced that’s really an option with the confidentiality requirement
<@py0xc3:fedora.im>
15:32:38
So if we want to have a worst case alternative in place if both alternatives break away, though I'm not convinced of that
<@salimma:fedora.im>
15:33:29
annoying as it is, the one time I needed to coordinate embargoed stuff with people who don't want to use encrypted email or Matrix we ended up on ... Signal
<@jforbes:fedora.im>
15:33:47
Signal isn't so annoying
<@py0xc3:fedora.im>
15:33:58
Well, having encrypted matrix or signal channels is not so bad
<@py0xc3:fedora.im>
15:34:15
at least secure. But vulnerable to too much traffic.
<@thebeanogamer:fedora.im>
15:34:20
Not really equivilent to a proper ticket though
<@py0xc3:fedora.im>
15:34:25
Yes indeed
<@thebeanogamer:fedora.im>
15:34:27
These meetings are chaotic enough
<@py0xc3:fedora.im>
15:34:32
Not a sole solution on itself
<@thebeanogamer:fedora.im>
15:34:43
I don't want us to go round in circles too much
<@thebeanogamer:fedora.im>
15:34:52
So maybe we write this as if we have a private ticket platform
<@thebeanogamer:fedora.im>
15:34:57
And we revisit if that looks like it's going away
<@decathorpe:fedora.im>
15:35:18
that would be fine with me
<@py0xc3:fedora.im>
15:35:20
yes, +1. So writing it platform neutral.
<@thebeanogamer:fedora.im>
15:37:21
So then we've two tasks, writing the policy and creating the Bugzilla plumbing. We'll need a volunteer for the former (don't mind if it's me), the latter will need Alasdair's help
<@salimma:fedora.im>
15:37:21
yes, +1
<@py0xc3:fedora.im>
15:37:43
Ok, so, going ahead with the draft of mine? I already implemented the name of Conan Kudo 😌 , and have to review to ensure its neutral for the ticket platform.
<@py0xc3:fedora.im>
15:37:59
I'm happy if someone else wants to start with something else. Just wanted to get the discussion about contents started.
<@thebeanogamer:fedora.im>
15:38:12
Maybe PR what you've got so far against the docs site and we can review there
<@thebeanogamer:fedora.im>
15:38:15
As it needs to end up there anyway
<@conan_kudo:matrix.org>
15:38:42
we also still have gitlab.com/fedora FYI
<@py0xc3:fedora.im>
15:38:42
Yes, can do that. Need to improve text from the current bullet-point-only style anyway.
<@conan_kudo:matrix.org>
15:38:49
we can still use that for private tickets in a pinch
<@salimma:fedora.im>
15:39:05
that's better than freedesktop, yeah
<@thebeanogamer:fedora.im>
15:39:07
Something something xkcd 927
<@conan_kudo:matrix.org>
15:39:07
at least until fedora/redhat stops renewing the OSS gitlab arrangement
<@py0xc3:fedora.im>
15:39:13
Good point, I think I'm still developer there ^^ But not sure if I consider gitlab more private than freedesktop?
<@thebeanogamer:fedora.im>
15:39:28
GitLab's privacy is bound by contract
<@conan_kudo:matrix.org>
15:39:39
gitlab.com/fedora leakage is redhat's fault :)
<@py0xc3:fedora.im>
15:39:45
Partially, its a US company, which leads to restrictions.
<@conan_kudo:matrix.org>
15:39:50
per the arrangement with them and gitlab
<@py0xc3:fedora.im>
15:39:54
Not necessarily a game breaker of course, but still just another compromise
<@conan_kudo:matrix.org>
15:40:16
gitlab bv is dutch FYI
<@py0xc3:fedora.im>
15:40:33
The mother is not a US?
<@conan_kudo:matrix.org>
15:40:40
no
<@conan_kudo:matrix.org>
15:40:44
the parent company is Dutch
<@conan_kudo:matrix.org>
15:41:16
Ukrainian guy moved to Netherlands and founded the company to commercialize a side project
<@conan_kudo:matrix.org>
15:41:20
that's how GitLab started
<@py0xc3:fedora.im>
15:41:25
Interesting. Anyway, don't see this too critical in this particular case.
<@thebeanogamer:fedora.im>
15:41:35
Ok so we have an action item there to make the PR
<@py0xc3:fedora.im>
15:41:35
So I'm fine anyway
<@py0xc3:fedora.im>
15:42:02
I would draft for now neutrally, and just add a specific place to fill in gitlab, bugzilla, forge, or whatever, and keep this part easy-to-update
<@py0xc3:fedora.im>
15:42:04
if that is ok?
<@conan_kudo:matrix.org>
15:42:42
πŸ‘οΈ
<@py0xc3:fedora.im>
15:42:42
!action @py0xc3 to put the current draft for the policy of #13 into a PR against the security team docs
<@py0xc3:fedora.im>
15:42:54
Ok, anything else on the topic?
<@thebeanogamer:fedora.im>
15:43:05
In terms of Bugzilla, does the proposed architecture of a `Fedora Security` component with a dedicated service `Embargoed Bugs` make sense?
<@thebeanogamer:fedora.im>
15:43:19
And would we want to sign that service up to the list directly or rely on list members raising bugs?
<@conan_kudo:matrix.org>
15:43:37
the former
<@salimma:fedora.im>
15:44:01
so that would make sense, yeah, and once the embargo is lifted we can either reassign the bug to the real component or open a new one I guess?
<@py0xc3:fedora.im>
15:44:05
+1, the other might cause bottlenecks
<@salimma:fedora.im>
15:44:07
I guess open a new linked bug is better
<@conan_kudo:matrix.org>
15:44:10
yup
<@conan_kudo:matrix.org>
15:44:22
I think that's a case-by-case issue
<@jforbes:fedora.im>
15:44:31
reassign is typical, no need to hide once embargo is lifted
<@conan_kudo:matrix.org>
15:44:43
e.g. when I handled a PackageKit CVE, I made a new bug because the original contained a PoC exploit that we didn't want to disclose
<@jforbes:fedora.im>
15:45:05
Oh, those should be private comments either way
<@conan_kudo:matrix.org>
15:45:07
if no sensitive data after the fact exists, no reason to not just reassign and make public
<@conan_kudo:matrix.org>
15:45:29
we can't make private comments currently, so it's not a feature I can rely on
<@thebeanogamer:fedora.im>
15:45:33
Yeah for Samba I know they do a mixture depending on what was written on the ticket
<@conan_kudo:matrix.org>
15:45:35
only Red Hatters can do that
<@salimma:fedora.im>
15:45:42
yeah, we have the option to do both anyway but probably safer to always just open a new linked bug
<@jforbes:fedora.im>
15:45:45
Oh :(
<@conan_kudo:matrix.org>
15:45:59
yeah, if it was a thing I could do, I would
<@jforbes:fedora.im>
15:46:04
But yeah, PoC should never be made public unless they are already public
<@conan_kudo:matrix.org>
15:46:08
it drastically simplifies things
<@jforbes:fedora.im>
15:46:15
Which, these days...
<@conan_kudo:matrix.org>
15:46:33
responsible teams don't do terrible things like zero-day the world
<@conan_kudo:matrix.org>
15:46:40
but some fools do, and then we're kind of stuck with it
<@conan_kudo:matrix.org>
15:47:00
again, case-by-case handling
<@thebeanogamer:fedora.im>
15:47:43
In terms of access to that new Bugzilla, I'd suggest we stick it behind a new FAS group whose members are the people on the list on our behalf
<@thebeanogamer:fedora.im>
15:48:27
"Security Bug Handlers" or something like that
<@conan_kudo:matrix.org>
15:49:27
sec-bugzappers :)
<@py0xc3:fedora.im>
15:49:36
Yes, that might make sense. To not be bound to security sig members = private access
<@conan_kudo:matrix.org>
15:49:36
I'm a fan of the classics :)
<@thebeanogamer:fedora.im>
15:49:39
See that's much snappier
<@salimma:fedora.im>
15:50:09
I was trying to come up with a name but Neal nailed it
<@decathorpe:fedora.im>
15:50:13
(classics?)
<@salimma:fedora.im>
15:50:27
I missed the reference too tbh
<@conan_kudo:matrix.org>
15:50:27
our original bug triage team was called BugZappers
<@thebeanogamer:fedora.im>
15:50:34
Ok so two more items there. One to create the FAS group and one to create the Bugzilla
<@conan_kudo:matrix.org>
15:50:46
https://fedoraproject.org/wiki/BugZappers
<@decathorpe:fedora.im>
15:51:06
ah. so in the time before my Epoch 0 πŸ˜†
<@thebeanogamer:fedora.im>
15:51:19
On Bugzilla, https://forge.fedoraproject.org/security/tickets/issues/17 might go in there as well, but given nirik and friends are the ones responding to those alerts we should go wherever they want it
<@conan_kudo:matrix.org>
15:51:39
most of their functions were absorbed into Fedora QA
<@conan_kudo:matrix.org>
15:51:43
so the team withered away
<@thebeanogamer:fedora.im>
15:53:19
!action Create a `sec-bugzappers` FAS group for those on the `linux-distros` mailing list
<@py0xc3:fedora.im>
15:53:35
Can you do that one Daniel?
<@thebeanogamer:fedora.im>
15:53:42
I can certainly ask Infra to do it
<@py0xc3:fedora.im>
15:53:52
Cool :)
<@thebeanogamer:fedora.im>
15:54:07
!action Create Bugzilla home for `linux-distros` reports
<@thebeanogamer:fedora.im>
15:54:40
Cool, I think that's it in terms of stuff we needed to discuss
<@thebeanogamer:fedora.im>
15:54:48
Unless anyone feels like weighing in on https://forge.fedoraproject.org/security/tickets/issues/18 ?
<@py0xc3:fedora.im>
15:54:52
Yeah, more points about it from someone?
<@decathorpe:fedora.im>
15:55:13
not yet
<@py0xc3:fedora.im>
15:55:23
Ok, final topic
<@py0xc3:fedora.im>
15:55:31
!topic 2.2. Only Forge-owners can create repos in the security group: should Forge-members be allowed too?
<@py0xc3:fedora.im>
15:55:45
That's a simple thing: does everyone agree if I give Security SIG members the privilege to create/add/migrate repos in forge? So far only owners can do that. Members can already do PR and such. PR on linked/published repos is more invasive than creating new unlinked repos anyway, but I didn't want to make something that is formally invasive on my own without asking :)
<@salimma:fedora.im>
15:56:06
how about something related - a badge for fixing security bugs?
<@decathorpe:fedora.im>
15:56:27
+1 to allow members to create repos.
<@py0xc3:fedora.im>
15:56:29
Ah, didn't see another topic was raised.
<@thebeanogamer:fedora.im>
15:56:31
I think there's already one for security-linked Bodhis
<@jforbes:fedora.im>
15:56:38
I don't know that I see a need to create repos
<@thebeanogamer:fedora.im>
15:56:38
Also +1 on this
<@py0xc3:fedora.im>
15:57:11
Most likely it will be for docs repos
<@decathorpe:fedora.im>
15:57:15
need - maybe not, but I do think it's weird that there's second-class group members :)
<@py0xc3:fedora.im>
15:57:17
That's where the issue just came up,
<@thebeanogamer:fedora.im>
15:57:35
https://badges.fedoraproject.org/badge/white-hat
<@salimma:fedora.im>
15:57:36
we can try reenabling and see if it gets abused (hopeefully not)
<@py0xc3:fedora.im>
15:57:39
It doesn't really add risks, given that we are already careful with memberships, and they can already do PR
<@salimma:fedora.im>
15:57:49
because in a pinch it might be annoying if you really need to make a repo and nobody is around
<@py0xc3:fedora.im>
15:57:57
Ok, then I enable it.
<@py0xc3:fedora.im>
15:58:07
!action @py0xc3 to add repo create privilege to security sig members
<@py0xc3:fedora.im>
15:58:11
That's it
<@py0xc3:fedora.im>
15:58:13
!topic open floor
<@py0xc3:fedora.im>
15:58:20
... which I assume is badging related :)
<@decathorpe:fedora.im>
15:58:43
I'll drop at :00 - or melt into a puddle, whichever happens first
<@salimma:fedora.im>
15:59:09
we could probably make white hat tiered
<@salimma:fedora.im>
15:59:12
but eh
<@salimma:fedora.im>
15:59:19
yeah I need to go and charge my car
<@py0xc3:fedora.im>
15:59:28
Daniel Milnes: shall I put #18 to the agenda for next week?
<@salimma:fedora.im>
15:59:32
and then I need to badge back into the office, yes
<@thebeanogamer:fedora.im>
15:59:41
Couldn't hurt
<@py0xc3:fedora.im>
15:59:48
Ok. I'll do
<@py0xc3:fedora.im>
16:00:10
Since some are leaving or have already left, I assume we can end the meeting?
<@salimma:fedora.im>
16:00:18
I think so... thanks for chairing
<@py0xc3:fedora.im>
16:00:27
ok, thanks for being here evreyone :)
<@zodbot:fedora.im>
16:00:37
decathorpe gave a cookie to py0xc3. They now have 6 cookies, 3 of which were obtained in the Fedora 44 release cycle
<@py0xc3:fedora.im>
16:00:48
!endmeeting