14:00:33 #startmeeting Security Team Meeting - Agenda: https://fedoraproject.org/wiki/Security_Team_meetings 14:00:33 Meeting started Thu Apr 9 14:00:33 2015 UTC. The chair is Sparks. Information about MeetBot at http://wiki.debian.org/MeetBot. 14:00:33 Useful Commands: #action #agreed #halp #info #idea #link #topic. 14:00:36 #meetingname Fedora Security Team 14:00:36 The meeting name has been set to 'fedora_security_team' 14:00:46 #topic Roll Call 14:00:48 * Sparks 14:00:50 .hellomynameis pjp 14:00:51 pjp: pjp 'None' 14:01:09 .fas bvincent 14:01:09 bvincent: bvincent 'Brandon Vincent' 14:03:32 * Sparks updates the agenda... again. 14:04:45 jsmith: You will be called upon 14:06:30 Okay, let's get started. 14:07:03 #topic Follow up on last week's tasks 14:07:17 #action jsmith to patch rubygem-activesupport as provenpackager (BZ 905374) 14:07:25 * Sparks thinks jsmith isn't around this morning 14:07:53 #info jsmith was having problems with this package since it's ruby. He may have found some assistance with it, however. 14:08:01 I think jsmith did patch it, IIRC 14:08:18 pjp: He did and it failed. 14:08:24 pjp: start non-responsive maintainer against rubygem-activesupport in EPEL6 14:08:38 Did you do this? 14:08:44 Sparks: done, I'have filed a bug, no reply so far 14:09:11 pjp: Okay, how long are you supposed to wait? 14:09:12 -> https://bugzilla.redhat.com/show_bug.cgi?id=1209124 14:09:36 Sparks: For two weeks we need to ping on this bug for any response, 14:09:44 #info pjp started the non-responsive maintainer procedure on rubygem-active support 14:09:53 #link https://bugzilla.redhat.com/show_bug.cgi?id=1209124 14:10:20 pjp: Okay, I'm assuming you're handling this. I'll put an action item in the minutes for next week. 14:10:28 Sparks: in the third week we send an email to the -devel list about potentially orphaning the said package or retiring it from the branch 14:10:35 Sparks: Yes, 14:10:51 #action pjp to continue monitoring the non-responsive maintainer for rubygem-activesupport. Follow up in one week. 14:11:18 * pjp also planning to run the script to ping on old long-standing security bugs 14:11:23 #info Sparks did discuss the 90-day challenge with the Security Team (more on that later) 14:11:30 pjp: +1 14:11:52 pjp: I actually did that, myself, on Monday and it seemed to have kicked a few into gear. 14:12:05 Sparks: Oh, cool! :) 14:12:24 #info Sparks closed all retired-package CVE tickets for EPEL 14:12:41 Anything else on old tasks? 14:13:58 Nope, 14:14:20 Sorry, I'm still working on some numbers.... 14:14:32 I'm going to go out of order for a moment 14:14:37 #topic Outstanding BZ Tickets 14:14:46 #info Thursday's numbers: Critical 1, Important 41 (-7), Moderate 350 (-29), Low 163 (-7), Total 556, Trend -43 14:14:53 #info Current tickets owned: 147 (~26%) 14:14:59 #info Tickets closed: 271 (+22) 14:15:20 Looks like we've got some motion. 43 tickets closed in a week is good! 14:16:07 Wow! :) 14:16:18 nice 14:18:23 Sorry, I'm still working on challege numbers 14:18:33 Does anyone have anything to discuss around this topic? 14:20:11 Challenge numbers? 14:20:59 #topic 90-Day Challenge 14:21:07 #info 90-Day Challenge has a goal to close all 2014 and prior Important CVEs in Fedora 14:21:43 #info of the 38 Important CVEs, 1 has been closed, 8 are On_QA 14:21:56 So after a week we're starting to see some movement. 14:22:20 #info Many of these tickets haven't been followed up on in recent times and should be. 14:22:44 #info Sparks will unassign tickets from fst_owners if they don't follow up within a week. 14:23:33 I'm still working on challenge prizes but I do have a budget. 14:23:39 Questions? Comments? 14:24:20 none from me 14:24:43 #action Sparks to blog about the challenge 14:24:53 #topic Open floor discussion/questions/comments 14:24:59 Okay, anyone have anything? 14:25:13 Nope, 14:25:34 Sparks: What are options for prizes? 14:26:27 pjp: Not sure. I was looking for something in the Red Hat Cool Stuff Store since it would be easy to obtain and ship. I've also been contemplating t-shirts for the team. 14:26:35 * Sparks is open to ideas. 14:29:34 Okay, if no one has anything else we'll close for the day. 14:30:55 Sparks++ 14:31:20 free prizes :) 14:31:51 randomuser: Yep, all you have to do is close more Important CVEs that me! :) 14:32:22 does WONTFIX count? 14:32:24 * randomuser ducks 14:32:52 randomuser: Only if you get the package retired. 14:33:36 :) 14:34:16 Sparks: may be Caps could be an option too, 14:35:17 uniform shirts, with Fedora Security Team badges 14:35:46 pjp: Sure 14:36:04 randomuser: yeah, the idea has been in progress although we'd need a logo. 14:36:16 And no one wants any logo I'd design. 14:36:35 :) 14:36:46 Okay, we can move this discussion to #fedora-security-team. 14:36:51 Everyone have a good day! 14:36:54 #endmeeting