layout | toc | meeting_time | title |
---|---|---|---|
page |
true |
June 19th, 2024 16:00 UTC |
Minutes 2024-06-19 |
2024-06-19 16:00 UTC @ TPRF Slack #cpan-security channel
- @sjn
- @stigtsp
- @timlegge
- @book
- @leont
- @Tux
- @garu
- @stigtsp - hoping to get cpanm with https by default into the official perl docker images. There are pull requests for this in cpanminus . @garu is planning to do the PR for docker images.
- Cleanest way is a build
- @sjn: Solicited feedback from OpenSSF's SBOM Everywhere SIG. A recording from the meeting is online.
- @sjn shared his documentation with the SIG. Will have a meeting with Josh Bressers so the document can be more useful for wider commumity - work continues
- @timlegge: Sent in another request via cve.mitre.org and then asked them for an update - copied mailing list.
- @leont has started writing something - not alot of time
- Needs to make a little more sense before sharing
- @book will reach out next week
- @sjn: New criteria found here
- New policies for the picking
- Reduced the minimum amount to make the applications for - 50K instead of 150K
- Should we push TPRF to find projects to sponsor.
- TPRF may be able to assist in the money management
- Create a list of modules/dists that should be considered for CPAN to be "Secure by Default". stigo to creat a list as a start
- @sjn: WG is slowly starting. Links to WG resources added to the reading list page.
- @sjn: Planning on writing an "intro to CRA page" based on his PTS talk
- Goal to ensure the right questions are asked
- Reach out if you have time and are interested in helping
- @sjn: Work expected to begin in June. @sjn intends to be active there.
- Opensource project sustainability fields to show that a project needs help for its future (help or funding, etc.)
- Check out and comment on the issue if you are interested
- May need to register some CVE's for two new vulns that was added to CPAN::Audit
- Need to start up the CVE request for old vulnerabilities again
- Open Source event in Vienna in September?
- London Perl Workshop - October? - possible talk opportunities
- What is the point of PURLs? - @sjn has started putting together a blog post on the why.
- July 03, 2024 1700 UTC