14:26:34 <aimeeu> #startmeeting Security Subcommittee 14:26:34 <collabot_> Meeting started Tue Jun 26 14:26:34 2018 UTC. The chair is aimeeu. Information about MeetBot at http://wiki.debian.org/MeetBot. 14:26:34 <collabot_> Useful Commands: #action #agreed #help #info #idea #link #topic. 14:26:34 <collabot_> The meeting name has been set to 'security_subcommittee' 14:26:45 <aimeeu> #chair aimeeu, bryan_att 14:26:45 <collabot_> Current chairs: aimeeu bryan_att 14:26:58 <aimeeu> #topic Jira tasks 14:27:40 <aimeeu> #info Bryan created tag in Jira for all security items; items are displayed on Security wiki page 14:28:45 <aimeeu> #info these Jira items are for all security-related tasks across all components 14:29:03 <aimeeu> #info attendees Bryan, Aimee Ukasick, Vineet Tripathi 14:29:41 <aimeeu> #info the Security committee needs to work with projects to prioritize existing Jira items 14:30:10 <aimeeu> #topic Validation-Security component 14:30:30 <aimeeu> #info page created in the Common Services project's wiki space 14:30:47 <aimeeu> #info #link https://wiki.acumos.org/display/CS/Validation-Security 14:31:39 <aimeeu> #info Vineet: are all of these related to November release? Bryan: yes 14:32:27 <aimeeu> #info Vineet (Portal team) will work with Mukesh to schedule work on these tasks 14:33:54 <aimeeu> #topic Goals for Athena 14:34:09 <aimeeu> #info #link https://wiki.acumos.org/display/SEC 14:34:26 <aimeeu> #info Bryan: unsure if Community is ready to stand behind these goals 14:34:57 <aimeeu> #info how the ecosystem has to operate in terms of "trust" 14:36:39 <aimeeu> #info need to ensure a federated system that I am connected to isn't a threat 14:37:44 <aimeeu> #topic Validation-Security component 14:38:23 <aimeeu> #info needs to be a main focus since it is the most problematic 14:38:48 <aimeeu> #info #link https://wiki.acumos.org/display/CS/Validation-Security 14:39:57 <aimeeu> #info #link https://jira.acumos.org/browse/ACUMOS-1041 14:43:24 <aimeeu> #info #link https://jira.acumos.org/browse/ACUMOS-1176 14:54:03 <aimeeu> #info discussion on k8s job to trigger scan using 3rd party open source tools 14:54:31 <aimeeu> #info Vineet will check into getting resources 14:54:50 <aimeeu> #info discussion on what the current validation component does 14:55:34 <aimeeu> #endmeeting