13:02:24 #startmeeting Security Team Meeting - Agenda: https://fedoraproject.org/wiki/Security_Team_meetings 13:02:24 Meeting started Thu Oct 23 13:02:24 2014 UTC. The chair is Sparks. Information about MeetBot at http://wiki.debian.org/MeetBot. 13:02:24 Useful Commands: #action #agreed #halp #info #idea #link #topic. 13:02:27 #meetingname Fedora Security Team 13:02:27 The meeting name has been set to 'fedora_security_team' 13:02:32 #topic Roll Cal 13:02:34 .hellomynameis jsmith 13:02:35 jsmith: jsmith 'Jared Smith' 13:02:35 #undo 13:02:36 Removing item from minutes: 13:02:36 .fas bvincent 13:02:39 bvincent: bvincent 'Brandon Vincent' 13:02:40 #topic Roll Call 13:02:42 * Sparks 13:02:45 hello 13:02:47 here 13:02:52 Morning all 13:02:54 morning 13:10:43 Shall we continue? 13:11:25 jsmith: Sorry, I'm trying to catch up numbers... 13:11:37 Ah :-) 13:12:22 Sorry, it's been a morning here.... 13:12:28 #topic Outstanding BZ Tickets 13:12:45 #info Thursday's numbers: Critical 1, Important 50, Moderate 342, Low 122, Total 515, Trend -17 13:12:53 #info Current tickets owned: 166 (~32%) 13:13:00 #info Tickets closed: 128 13:13:13 Anyone have any ticket issues they'd like to talk about? 13:17:17 #topic Open floor discussion/questions/comments 13:17:27 Anyone have anything they want to talk about? 13:18:05 nothing on my side, just been working on contacting maintainers 13:18:28 which is a sort of adventure by itself 13:20:07 On the bright side, Fedora 19 support will be EOL soon. 13:20:39 jtaylor90: Yes, I like it when they say sorry busy right now could you take care of it... 13:21:29 d-caf: hah yeah that's a favorite 13:21:55 Sparks: did you or someone get all the orphaned package tickets already? 13:23:21 just curious if there will be a large ticket drop once the epel orphan package report items start being retired 13:24:17 jtaylor90: I picked up the orphaned tickets for EPEL a while back. I haven't checked for them recently. 13:24:30 jtaylor90: I suspect there will be. 13:25:00 gotcha 13:27:03 Is there any kind of framework or process we could leverage to get the tickets more visibility? 13:27:35 for instance, a BZ gets opened for a package, no response from the package maintainer in x time, sends the ticket to releng 13:27:44 (or provenpackagers) 13:28:08 yeah or that :) 13:31:35 jtaylor90: And I think jsmith is a proven packager. 13:31:36 :) 13:31:43 Okay, anyone have anything else? 13:31:48 so forward everything to jsmith? :) 13:31:53 jtaylor90: Yes 13:32:09 perfect 13:32:10 jtaylor90: Start by forwarding one or two things to me, and I'll see if I can keep up with the workload 13:32:13 :-) 13:32:23 But yes -- I'm willing to try to work on issues as I'm able 13:32:29 I already average one or two a week 13:33:14 nice 13:33:58 If there's anything in particular you want me to look at today, let me know, as today is a good day :-) 13:34:35 awesome, I will follow up with you after this 13:35:03 I'm also thinking of a weekly email to the -devel list letting people know of unhandled issues might be appropriate 13:35:37 ... hoping that more provenpackagers will *see* that there are issues that we need help with, even if they don't attend this meeting 13:36:01 seems like that would be frequent enough to be visible but not spamish 13:37:28 jsmith: +1 13:37:36 jsmith: It would be nice to automate that. 13:37:57 +1 from me if it matters lol 13:38:09 Sparks: We'll work on that :-) 13:38:51 Who had those rubygem BZ reports? 13:38:51 #action jsmith to figure out how to send an email to {fedora,epel}-devel regarding unhandled security bugs. 13:39:48 bvincent: I'm not sure :-( 13:39:59 It looks like new rubygems packages will be reaching EPEL soon. 13:40:43 bvincent: Oh, yes, they got moved this week. 13:41:06 I think that was the only active Critical bug. 13:46:39 bvincent: We grew a new one 13:50:23 Sparks: Which I only see that one in crit, or is it yet to be released 13:51:43 d-caf: No, that's the one 13:51:52 Okay, anyone have anything else? 13:52:00 * Sparks needs to get ready for his next meeting. 13:52:12 nothing else here 13:52:18 all set here 13:53:08 I think this is the longest a meeting has gone... 13:53:41 Okay, thanks for coming out! We'll see you around the Internetz. 13:53:44 #endmeeting