Attendees: 



Agenda Item NotesOwnerActions / Next Steps
Updates on Release 1.9
  • #15164: td-agent version pinning
  • #15520: Cwag-CI taking huge disk-space
  • #15217: NMS yarn test (unit test) failing
  • #15222: Summarizing the current state of CI Issues.

Sikander-Wavelabs


Lucas reached out to yogesh, for C++ changes and new feature changes to look into security POV for 1.9, no longer blocked on CI/CD dashboard, next eng meeting need to review old prs and start cleaning up. 

  • Yogesh catch up with features group to pick release date: No discussion as the participation was very low.
  • Jordan → propose mid august for 1.9 release date, discuss when we have quorum of TSC members
  • Max - has not been a pr since 2nd may : Need to fix other CI issues (like CWAG, NMS)
  • Jordan→ Ubuntu, need to plan upgrade, bring to features group
Bug Bounty Program


  • Ben - discuss "pay for work" model 
  • Lucas proposed "refactor reviewdog-workflow.yml for security" https://github.com/magma/security/issues/147

  • Som proposed windowing scheme
  • The Security WG discussed disclosure of security weakness in bounties for fixing them.


  • Hackerone likely not the right platform. Given use cases we would use Github sponsorhsips.
  • Arrived on policy for disclosing security issues: ok to disclose if trivial, otherwise we will reserve bug bounties for trusted contributors.
  • Refactoring reviewdog-workflow.yml approved. Lucas to move the issue from the security repo to the public repo. (https://github.com/magma/magma/issues/15192)
  • Bounty amounts need to be defined
  • Shubham to document two bounty proposals: upgrade Kubernetes; create CI job to scan Docker images for vulnerabilities using trivy
  • Som to create a page in the LF wiki on the bounty program.

  • Need draft Quickstart for anyone who wants to recommend a bug bounty program (process & timeline) - Jordan will start doc, Ben add in budget info. Bounty Program Process
    [ NEED TO CLOSE THIS - TSC members please review/comment]
  • Folks will review and comment this week
  • Ben Reward readme document needs to be written and vetted by LF legal.
  • Discuss in outreach Decide on budget and budget per issue.
Outreach Report
  • Action items and next steps are captured in document
  •  Pick topics and date for next town hall
  • Develop aggressive comms plan as part of town hall planning

Other:

  • eBPF 
General discussion on interest in eBPF project (migration from OVS)@Pravin Shelar
  • Shubham Tatvamasi , Suresh (Wavelabs), Som are interested
    @pbshelar@fb.com will start the document. Contact him over slack if you are interested in participating.
Branch protectionTo enable the CI dashboard fix to go into production ASAP, Max had to suspend branch protection rules in order to enable force merging. Let's discuss when and how to take this step in the future.
    • TSC Will Vote On The Following
      • Force merging is off by default
      • Only Linux Foundation, IE Benjamin Sternthal, is allowed to set it to on.
      • LF may only enable it by vote of the TSC.
    • Requires 4 present for quorum
    • Vote will be recorded here
Security issue 151Pause recordingLucas Gonze 
Review Latest Q&A In Github, Review Slack For Candidate Github Topics

Recording:

https://zoom.us/rec/share/FHAUKUaj62TRDr57P7pX-7KWAaJ34aM0nY3gECOjHhMvR_7030XP_2r6nWJQPWDK.GVaPGo-SaPsi9M8g

  • No labels
Write a comment…