14:01:35 #startmeeting Security Team Meeting - Agenda: https://fedoraproject.org/wiki/Security_Team_meetings 14:01:35 Meeting started Thu Aug 20 14:01:35 2015 UTC. The chair is Sparks. Information about MeetBot at http://wiki.debian.org/MeetBot. 14:01:35 Useful Commands: #action #agreed #halp #info #idea #link #topic. 14:01:38 #meetingname Fedora Security Team 14:01:38 The meeting name has been set to 'fedora_security_team' 14:01:40 #topic Roll Call 14:01:41 * Sparks 14:01:44 * d-caf 14:01:50 * scorneli 14:01:56 * mhayden woots 14:03:37 * Sparks updates the agenda 14:05:36 jsmith: Wake up! 14:06:43 Hello, 14:06:56 pjp: Hello, we are in roll call now :-) 14:07:14 d-caf: Hi, cool! 14:07:15 Okay, lets get started. 14:07:21 #info Participants are reminded to make liberal use of #info #link #help in order to make the minutes "more better" 14:07:27 #topic Follow up on last week's tasks 14:07:35 #action Sparks to update the FST_numbers script to show the %age of tickets owned for each category. 14:07:44 Was there anything else from last week that needed discussing? 14:09:01 #topic Outstanding BZ Tickets 14:09:09 #info Thursday's numbers: Critical 0 (0), Important 37 (-9), Moderate 365 (-4), Low 145 (-7), Total 525 14:09:15 #info Current tickets owned: 82 (~16%) 14:09:19 #info Tickets closed: 369 (+9) 14:09:31 Anyone have anything they'd like to discuss that's bug related? 14:10:18 scorneli: Thanks for reaching out the the redhat person on that ticket, they were able to close it as does not apply as he wasn't building in that compononet (I wasn't sure) 14:10:42 d-caf: sure, np 14:11:01 nope, 14:12:18 Anything else? 14:12:34 nothing for me 14:13:06 #topic Open floor discussion/questions/comments 14:13:12 Anyone have anything at all? 14:13:39 #link https://bugzilla.redhat.com/show_bug.cgi?id=1243790 fyi, this is a RFE I've filed to include a mechanism to warn about orphaned packages etc in dnf 14:13:43 i talked a bit about the FST at Flock last week with some folks 14:13:59 it might be helpful if we listed 2-3 ways that beginners could contribute to our efforts 14:14:20 i think some folks feel like they need to be a software developer and/or infosec expert to help us 14:14:28 mhayden: True, there were similar questions at FUDCon APAC too, 14:14:45 we could bounce some ideas around on the ML and make a fedora magazine post 14:14:54 mhayden: Yep 14:15:00 also, check out Mairin's proposed Fedora Hubs stuff 14:15:09 would be awesome to have a security hub that's really welcoming 14:15:10 moar marketing! 14:15:14 MOAR 14:15:31 not sure if her slides are up yet 14:15:39 i know her intern (forgot her name!) had some things on a blog 14:16:19 * scorneli is entirely unaware of fedora hubs. but i'll google it 14:16:59 #link https://fedoraproject.org/wiki/Fedora_Hubs 14:17:19 * mhayden tips his hat to scorneli 14:18:15 #idea FST should have a hub 14:18:26 * d-caf Thinks we all need red fedoras with security badges on them... 14:18:44 * mhayden giggles 14:19:08 i'll offer to hammer together some markdown for a fedora magazine post if someone would want to help me edit/improve it 14:19:11 d-caf: You mean blue fedora 14:19:27 mhayden: I'll help 14:19:30 * d-caf Thinks we all need blue fedoras with security badges on them... 14:19:46 d-caf: +1 14:20:01 Sparks: okay, i'll try to get something going in a github gist perhaps 14:20:25 mhayden: let's open an etherpad for the post, 14:20:27 #action mhayden to draft a post for fedora magazine about getting involved with FST 14:20:36 pjp: which etherpad 14:20:55 mhayden: https://piratepad.ca 14:21:18 mhayden: Just provide the link when you can 14:21:25 can do 14:21:59 mhayden: I can try to assist as well 14:21:59 Anything else? 14:22:06 woot 14:22:26 we need a zodbot ping for this meeting, I forgot again 14:22:52 zoglesby: It's called a calendar. 14:23:26 Sparks: calendars are hard 14:23:41 zoglesby: And you even have an OwnCloud instance to abuse! 14:24:14 my owncloud is all broken after an upgrade, I need to fix it. 14:24:34 but that is neither here nor there 14:24:42 zoglesby: Haven't you learned anything about running a production system? Never upgrade. Ever. 14:24:50 Okay, anyone have anything else? 14:25:00 - 14:25:06 scorneli: Go 14:25:19 oh, sorry, that should signal a "no" 14:27:07 Okay, if there is nothing else... 14:27:56 #endmeeting