===================== #lfn-meeting: LFN_TAC ===================== Meeting started by phrobb at 14:02:02 UTC. The full logs are available at http://ircbot.wl.linuxfoundation.org/meetings/lfn-meeting/2018/lfn-meeting.2018-08-29-14.02.log.html . Meeting summary --------------- * Frank Brockners (frankbrockners, 14:03:04) * Tapio Tallgren (ttallgren, 14:03:16) * Jason Hunt, IBM (JasonHunt, 14:03:26) * LINK: https://zoom.us/s/468557487 is outdated - that was the old invite from Ray Paik (frankbrockners, 14:05:42) * Greg Elkinbard (GregElkinbard, 14:06:48) * ACTION: kennypaul send new bridge, kill ghosts and point to wiki for zoom info (kennypaul, 14:10:37) * LINK: https://zoom.us/j/560486345 (kennypaul, 14:10:50) * Agenda (CaseyLF, 14:11:31) * Greg asked that the topic of Budget Deliverables be added to the schedule. (CaseyLF, 14:16:10) * Nexus IQ and Security Scanning (CaseyLF, 14:16:13) * phrobb says that ONAP dependency vulnerabilities will hinder ONAP CII badging (dmcbride_, 14:17:11) * It would be a good idea to have the security teams across all projects. (CaseyLF, 14:17:22) * Sonotype do not want the results of their scanning to be public. (CaseyLF, 14:17:41) * The CLM running has been shut off for about a week now. We are working with them to resolve their concerns. (CaseyLF, 14:20:27) * edwarnicke has concerns that this change doesn't fit in the Open Source project space. (CaseyLF, 14:21:31) * Sonotype has implemented a build flag which will prevent proprietary data from being logged (dmcbride_, 14:23:32) * phrobb suggests a TAC working group to review alternatives to Sonotype (dmcbride_, 14:30:21) * @GregElkinbard suggests looking at WhateSource (kennypaul, 14:31:06) * ACTION: Kenny/Casey to find out the specific product name that we are leveraging from Sonotype and send that to the TAC. (CaseyLF, 14:32:06) * LINK: https://www.blackducksoftware.com/sites/default/files/images/Downloads/Reports/USA/ForresterWave-Rpt.pdf (kennypaul, 14:35:22) * Working with CII presents an issue if you have more than one repo. (CaseyLF, 14:37:29) * workgroup would review available solutions, work with the projects and putting together a POC (kennypaul, 14:39:17) * ACTION: kenny/phill to start the conversation (kennypaul, 14:40:30) * Cross Project Testing (CaseyLF, 14:40:52) * "conversation" in action item regarding the creation of a workgroup (kennypaul, 14:41:55) * Jamil states that their has been conversation regarding Cross Project Testing and that he will be ready with a more formal presentation next week. (CaseyLF, 14:45:03) * He asked if anyone had some feedback regarding the topic. (CaseyLF, 14:45:46) * GregElkinbard requests to be added to the group participating. (kennypaul, 14:46:44) * from zoom chat- From Brian to Everyone: (07:50 AM) (kennypaul, 14:52:14) * from zoom chat- From Greg Elkinbard to Everyone: (07:51 AM) (kennypaul, 14:52:43) * Jamil will send a prop[osal when ready (kennypaul, 14:54:05) * TAC chair responsibilities (kennypaul, 14:57:56) * edwarnicke suggest clarity on TSC meeting attendance (kennypaul, 14:58:28) * discussion regarding attendance requirements (kennypaul, 15:00:24) * last bullet is specifically to "represent all of the technical communities to the board" (kennypaul, 15:03:15) * it is an attempt to address the issue of the Board declining to have TAC members on the Board. (kennypaul, 15:03:54) * brian freeman suggests change the 5th bullet - and add a second slide on what we really think should happen is direct project TSC to the board (kennypaul, 15:04:35) * ACTION: CaseyLF / kennypaul to flesh out the specifics and circulate via email (kennypaul, 15:06:23) * topic budget deliverables (kennypaul, 15:08:15) * question about infrastructure (kennypaul, 15:09:27) * ACTION: LF to post budget deliverables and deadlines and post it on the wiki (kennypaul, 15:10:04) * A&F committee mostly on holiday - have not met. (kennypaul, 15:11:25) Meeting ended at 15:12:34 UTC. Action items, by person ----------------------- * CaseyLF * CaseyLF / kennypaul to flesh out the specifics and circulate via email * kennypaul * kennypaul send new bridge, kill ghosts and point to wiki for zoom info * CaseyLF / kennypaul to flesh out the specifics and circulate via email * **UNASSIGNED** * Kenny/Casey to find out the specific product name that we are leveraging from Sonotype and send that to the TAC. * kenny/phill to start the conversation * LF to post budget deliverables and deadlines and post it on the wiki People present (lines said) --------------------------- * kennypaul (27) * CaseyLF (17) * TNadeau (12) * collabot (7) * dmcbride_ (5) * frankbrockners (4) * GregElkinbard (3) * phrobb (3) * ttallgren (2) * JasonHunt (1) * edwarnicke (1) Generated by `MeetBot`_ 0.1.4