layout | toc | meeting_time | title |
---|---|---|---|
page |
true |
July 03, 2024 17:00 UTC |
Minutes 2024-07-03 |
2024-07-03 17:00 UTC @ TPRF Slack #cpan-security channel
- @sjn
- @stigtsp
- @timlegge
- @book
- @Tux
- @garu
- @leont
- Something with better audio quality
- That doesn't require invites/sign-in
This meeting was done in Element/[Matrix], which uses Jitsi. Went well.
- We have sent PRs to master and development
- An independent PR has been sent into the official perl-docker image.
- Trying to push for use of the new patched version
- Some argument about whether to accept into the docker images.
- @Tux mentioned the fallback is needed - an environment variable would suffice
- @timlegge: Mitre finally got back to me and has some information they need as well as scheduling a meeting with them to discuss
- @timlegge Stig and I are discussing
- We could use some additional help as we go further with a CNA Please reach out if you have time and an interest.
- @leont said "I did start working on that", but hasn't shared a document yet
- New PSC will likely support HTTPS in core - there will be a meeting between old and new and it will likely continue
- @sjn suggests a poll of who can commit time to the work that could be started based on an application
- Peter will help post US Perl conference
- We need someone who can do project management.
- @stigtsp and @garu are putting together a list
- Sigstore and TUF could/should be on the list
- @sjn - goal is to give feed back on the EU standards and regulations
- Project has a technical lead
- TPRF is a foundation, and Perl NOC hosts code. In theory neither can join the organization - an org needs to both host and be a foundation/non-profit.
- @sjn - talked to someone who is working in the sustainability of open source projects
- @sjn - no update
- @stigtsp mentioned needing to look at registering CVE for that.
- @sjn - has been sharing and still a WIP. The contents are in a good place at this time.
- Please read and provide feedback if you can
- Discussed at the OpenSSF numerous times
The Perl and Raku Conference in Las Vegas, NV - June 24-28, 2024- Open Source Summit Europe in Vienna, Austria - September 16-18 + 19-20 - Lots of people from OpenSSF + SBOM + Supply chain security communities
- London Perl Workshop - Saturday 26th October 2024 - possible talk opportunities
- @Tux and @Tim worked on Crypt::OpenSSL::PKCS12
- @stigtsp how should a secure random module get moved to core? @garu explained the process for getting things moved into core - requests for comment, etc.