Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

August 7th, 2023 Community Meeting #155

Closed
qu1queee opened this issue Aug 1, 2023 · 2 comments
Closed

August 7th, 2023 Community Meeting #155

qu1queee opened this issue Aug 1, 2023 · 2 comments

Comments

@qu1queee
Copy link
Contributor

qu1queee commented Aug 1, 2023

  • Please add a topic in this thread and add a link to the GitHub issue associated with the topic.
  • Please make sure you give folks enough time to review/discuss the topic offline on GitHub before coming into the meeting
  • (optional) Paste the image of an animal 😸
@qu1queee
Copy link
Contributor Author

qu1queee commented Aug 1, 2023

@qu1queee
Copy link
Contributor Author

qu1queee commented Aug 7, 2023

Meeting minutes:

  • On the Hacktoberfest. Help us to get an understanding on where we are as a project. We can use this to get some SHIPs implemented. As a goal, we can aim for a 25% of the issues that are label with /hacktoberfest . Next steps, define issues and label them.
  • From CVE-2023-37264: Tekton Pipeline Vulnerability Impact on Shipwright build#1346, we considered to open it publicly due to its low severity. The community will work on hardening our setup, based on the exploit in Tekton, but we consider that this is not putting us at risk. Furthermore, we think it might be a good opportunity to explore how can SHP generate CVE's for its own packages. On CVE handling, we should consider to assess impact first(prior to CVE issue creation). @adambkaplan to follow-up on this with RH Security Team.
  • On v0.12.0 release, we did a weekly check on this, things are moving forward(webhook wise).
  • From @SaschaSchwarze0 , we are moving repos to go v1.20.* , probably a good idea for folks to do this locally.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant