Attendees:

 Benjamin Sternthal 

 Micky Kumar 

 Raphael Defosseux

Parthiban Nalliamudali  

Agenda:

Agenda Item NotesOwnerActions / Next Steps
Updates on Release 1.9
  • #15164: td-agent version pinning
  • #15161 might take more time as the flows are generated during bazel (update from Devops team).

Lucas reached out to yogesh, for C++ changes and new feature changes to look into security POV for 1.9, still blocked on CI/CD dashboard

Bug Bounty Program
  • Hackerone setup in progress
  • If you want to be subscribed to the bugbounty mailing list, please let ben know
  • Lucas proposed "refactor reviewdog-workflow.yml for security" https://github.com/magma/security/issues/147

  • Som proposed windowing scheme
  • The Security WG discussed disclosure of security weakness in bounties for fixing them.

  • hackerone in LF legal review
  • Arrived on policy for disclosing security issues: ok to disclose if trivial, otherwise we will reserve bug bounties for trusted contributors.
  • Refactoring reviewdog-workflow.yml approved. Lucas to move the issue from the security repo to the public repo. (https://github.com/magma/magma/issues/15192)
  • Bounty amounts need to be defined
  • Shubham to document two bounty proposals: upgrade Kubernetes; create CI job to scan Docker images for vulnerabilities using trivy
  • Som to create a page in the LF wiki on the bounty program.

  • Need draft Quickstart for anyone who wants to recommend a bug bounty program (process & timeline) - Jordan will start doc, Ben add in budget info.
Outreach Report
  • Action items and next steps are captured in document
  •  Pick topics and date for next town hall
  • Bevy page is live. Can tweak description, presenters as needed.

Other:

  • eBPF 
General discussion on interest in eBPF project (migration from OVS)Pravin Shelar
Community contribution: service conf scriptJavier Aubert has created a script*
 for getting all services running. Let's discuss how to move it forward.
  • reframe as docusaurus
What's Next For Magma

Review Latest Q&A In Github

Recording:

https://zoom.us/rec/share/2Rti11I3hgCM-IpTe_81wealxAQgdOFqQhBrDRff_PXLdYVAj5tmGxFOX2HG3WVS.NuAM0ye52sMC6RvS

  • No labels
Write a comment…