15:04:26 #startmeeting Validation and Security Team kickoff 15:04:26 Meeting started Wed Apr 18 15:04:26 2018 UTC. The chair is bryan_att. Information about MeetBot at http://wiki.debian.org/MeetBot. 15:04:26 Useful Commands: #action #agreed #help #info #idea #link #topic. 15:04:26 The meeting name has been set to 'validation_and_security_team_kickoff' 15:04:34 #info Aimee Ukasick 15:04:41 #topic Roll Call 15:04:46 #info Bryan Sullivan 15:09:19 # Info Nat TechM 15:09:38 # info 15:11:42 #info discussion about which project the validation-security component should be part of 15:13:33 #info discussion of end user experience for validation: built into portal; but component could be used by portal, on-boarding, federation 15:14:41 #action Bryan will document how the validation component works currently 15:15:09 #info Bryan asks for help documenting how validation works 15:15:38 #info Byran shows portal admin - configure workflow screen, which allows admin to include validation 15:15:55 #info Karrie notes that the functionality doesn't work quite right yet 15:17:05 #info Karrie notes that validation cannot be turned on via the Portal admin; it should be one already 15:19:00 #info Bryan notes that even though the validation containers are running, there are no logs being generated so maybe it's not being called 15:19:59 #info Karrie summarizes the vision of how validation should be configured using the portal admin - configure workflows screen 15:23:16 #info meeting attendees: Aimee Ukasick, Bryan Sullivan, Chris Lott, Karrie Hanson, Larry Uno, Mukesh Mantan, Nat Subramanian, Parichay 15:24:16 #info Bryan talks about goals for security scanning as outlined on #link https://wiki.acumos.org/display/AC/Security+Scanning 15:24:46 #info Bryan: use of third party tools may be needed 15:25:12 #info Ken Kristiansen 15:26:33 #info Bryan: content of models should be scanned for vulnerabilities 15:33:01 #info discussion of least privilege regarding deployment of model microservices 15:39:58 #info validation architecture should support "plug n play" of third party tools 15:45:57 #discussion should focus on a short-term plan 15:46:18 #info find tools to scan containers in nexus 15:53:30 #info Aimee: 3 things to do 1) scheduled or triggered scanning of nexus using a 3rd party tool for Developer challenge in May; 2) define use cases and architecture for integrating scanning into the platform (validation component); 3) long term planning on whether to force source code to be uploaded 15:55:08 #info third party tools: Fossology, OpenSCAP, OpenVAS, Clair 15:56:05 #info Devendra Sen 15:56:09 #endmeeting 15:56:46 #endmeeting 15:56:53 #endmeeting