14:01:29 #startmeeting OPNFV Security Meeting 20/07/2016 14:01:29 Meeting started Wed Jul 20 14:01:29 2016 UTC. The chair is lhinds. Information about MeetBot at http://wiki.debian.org/MeetBot. 14:01:29 Useful Commands: #action #agreed #help #info #idea #link #topic. 14:01:29 The meeting name has been set to 'opnfv_security_meeting_20_07_2016' 14:01:30 Hi * 14:01:37 ok.. 14:02:00 #agenda https://etherpad.opnfv.org/p/opnfv-sec-meetings 14:02:20 will give 2-3 mins for additions / amendments 14:03:48 k, should be short and sweet again 14:04:00 #topic security scanning 14:04:20 So TSC approved as a full project, as informed last week 14:04:32 We now have a dedicated jira: 14:04:55 good 14:05:16 #link https://jira.opnfv.org/projects/SECSCAN 14:05:30 git repo: 14:05:47 #link https://gerrit.opnfv.org/gerrit/#/q/project:securityscanning 14:06:05 wiki, we will continue to use the main security group wiki. 14:06:16 so I am building the wiki out on and off this week 14:06:42 in Jira I have built out the main epics / stories in general and towards D-release 14:07:07 I hope we will have ore people working with security scan 14:07:25 seems like we should, serverascode is getting involved. 14:07:35 and with it being a main project now, it will get more attention 14:07:38 good, 14:07:39 yup I am here, and will start to take a look today :) 14:07:58 thanks, very good 14:08:02 serverascode: cool! 14:08:12 I guess you can cover Luke when he is on vacation :) 14:08:36 I will be off for two weeks from Friday, so we won't do much, so its a good time to get famialir with it serverascode 14:08:56 sounds good 14:09:30 so we can get really stuck in after the summer break, as things will get busy around Colorado release 14:10:45 other then that there was a race condition that was causing some issues 14:10:51 but that is now fixed; 14:10:57 #link https://build.opnfv.org/ci/job/functest-apex-apex-daily-master-daily-master/66/console 14:11:13 'security_scan' 14:11:20 and you will see it running in the build 14:12:03 - - 2016-07-10 07:44:20,455 - run_tests - INFO - Running test case 'security_scan'... 14:12:29 serverascode: if you get stuck with anything, just drop me an email 14:12:48 ok 14:13:00 although all you need to do, is just run openscap manually from the CI 14:13:10 and check the result 14:13:43 so a health / sanity check to see what sort of state its in on Debian. I had a quick look and it seemed quite good 14:14:13 oh, when I say Debian, I mean the downstream..so Ubuntu 14:14:30 ok, that's it for now, unless any more questions.. 14:14:39 no questions right now 14:14:50 k, over to you Sona 14:14:57 #topic ci badge 14:15:23 As I mentioned in the meeting openstach had the badge now :) 14:15:45 which is good news 14:15:51 we are almost there 14:16:45 my issues are static and dynamic code analysis 14:16:53 be good to have that done, did you like the idea of doing it for overall opnfv, and then have the projects look at it? 14:17:11 I thought we can say "met" for static analysis 14:17:40 PEP8 & PyLint are run as gerrit gate jobs 14:17:45 right? 14:18:03 kind of, they are not security lints though 14:18:24 and techincally we don't run those gates on all code...so its not used for Java or C 14:18:37 Ok, we do the OPNFV project need to do in order to met this criteria? 14:18:49 If we try to do static analysis for all projects, it will be a nightmare logistically 14:19:02 haha 14:19:05 Sona: we put in a caveat 14:19:21 explain how we are upstream contributers with around 40 projects 14:19:30 what do yo mean by all projects? 14:20:01 we are just responsible for code which is generated by OPNFV project itself 14:20:48 well, each project will be responisble for their owm, with guidance from us and the badge program. 14:20:55 yes 14:21:17 so when we go forward, we do it for the overall OPNFV org, the website, the release ISO, developer guidelines etc. 14:21:39 when it come to the security of the code in every project, its going to be to tough to do that. 14:21:41 ok what should I say now? 14:21:50 unmet and some explanation 14:21:56 ? 14:22:05 yes, unmet (or N/A) if its available. 14:22:14 ok 14:22:21 and just pop the question into etherpad, and send it out. 14:22:26 and the same for dynamic analysis? 14:22:37 yes, both static and dynamic 14:23:16 perhaps we (security team) could doa threat analysis in the future instead? 14:23:34 instead of running dynamic analysis tool 14:24:27 if anyone wants to nominate for doing it we could, sure 14:24:36 ok :) 14:24:47 would be good to do it before Colorado 14:26:09 its just its quite a large undertaking without a few bodies on it 14:26:24 ok, so its good we are getting close now 14:26:29 top stuff 14:26:35 anything more Sona ? 14:26:43 when I chose unmet for dynamic analysis I get the question we we think it is ok that it is umnet, could you please help me to write something there 14:27:03 we we ="why" 14:28:24 sure! 14:28:26 np 14:28:34 but please use etherpad, rather then email 14:28:41 makes it easier to manage 14:28:46 ok, I will do 14:28:59 thanks 14:30:49 ok, np 14:30:59 #topic Any other business? 14:31:00 I don't have anything more about badge program 14:31:11 nope 14:33:03 ok, last of all. 14:33:12 Sona: are you ok too cover the next two weeks? 14:34:17 ping Sona 14:34:42 ok, I will drop her an email, if there is any change I will let all know 14:34:48 ok thanks everyone! 14:34:56 ok thanks :) 14:35:00 I will be back on the 8th August 14:35:04 #endmeeting