#mageia-dev Meeting
Meeting started by ennael at 19:10:04 UTC
(full logs).
Meeting summary
- build secteam team (ennael, 19:18:04)
- https://www.mageia.org/pipermail/mageia-dev/20110415/003999.html
(misc,
19:22:24)
- https://launchpad.net/~ubuntu-security
(pterjan,
19:42:53)
- https://launchpad.net/~ubuntu-security/+mugshots
(pterjan,
19:43:06)
- check the condition for handling private
exploit for bug (misc,
19:44:15)
- check that bugzilla can handle private bug (
based on ldap if possible ) (misc,
19:45:02)
- http://oss-security.openwall.org/wiki/vendors
(pterjan,
19:45:58)
- ACTION: boklm check
with debian people for the way they handle security (misc,
19:49:39)
- requires testing vm to be avaliable
(misc,
19:51:26)
- security@ should be sent to the team in charge
of security and should forward to sysadmin (misc,
19:55:59)
- http://www.bugzilla.org/features/#private
(pterjan,
20:01:11)
- ACTION: check if
exploit need to be kept private or not (misc,
20:03:18)
- ACTION: misc bring
the issue for next council meeting (misc,
20:09:17)
- http://oss-security.openwall.org/wiki/
(ennael,
20:12:30)
- http://article.gmane.org/gmane.comp.security.oss.general/4894
(stewb,
20:18:24)
- thread about the replacement of vendor-sec
http://thread.gmane.org/gmane.comp.security.oss.general/4650/focus=4894
(misc,
20:19:33)
- http://thread.gmane.org/gmane.comp.security.oss.general/4650/focus=4894
(boklm,
20:21:07)
- we should have 2 people for the vendor-sec
replacement (misc,
20:25:39)
- we should have at least 2 people for the
vendor-sec replacement ( but not too many ) (misc,
20:26:55)
- ACTION: ask to the
webteam about publish advisories (misc,
20:33:56)
- http://www.bugzilla.org/features/#custom-fields
seems the most appropriate (pterjan,
20:45:48)
- ACTION: sysadmins add
CVE field for the security category (misc,
20:51:51)
- ACTION: sysadmins add
security category (misc,
20:52:11)
- security bugs are assigned to bug triage team
for now, as everything is public (misc,
21:01:45)
Meeting ended at 21:09:53 UTC
(full logs).
Action items
- boklm check with debian people for the way they handle security
- check if exploit need to be kept private or not
- misc bring the issue for next council meeting
- ask to the webteam about publish advisories
- sysadmins add CVE field for the security category
- sysadmins add security category
Action items, by person
- boklm
- boklm check with debian people for the way they handle security
- misc
- misc bring the issue for next council meeting
- UNASSIGNED
- check if exploit need to be kept private or not
- ask to the webteam about publish advisories
- sysadmins add CVE field for the security category
- sysadmins add security category
People present (lines said)
- misc (128)
- pterjan (112)
- boklm (70)
- ennael (46)
- stewb (27)
- erzulie (14)
- shikamaru (13)
- spturtle (6)
- AndroUser2 (5)
- Kharec (3)
- dmorgan (2)
- Inigo_Montoya` (2)
- mikala (1)
- Ruperto (1)
Generated by MeetBot 0.1.4.