Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

TimeItemWhoNotes
5-10 minSpring RCE vulnerabilityAll

See https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement


Today:

  • Julian Ladisch has created a few JIRAs for this – he's still working on this.
  • He also wrote a script to list the affected modules - runs periodically
  • The edge modules are probably the most critical - 3 of them are affected.  The related POs are aware.
  • Should these fixes be backported to Kiwi?
    • Prevailing thought is that it should since Kiwi is the latest release and Lotus isn't official yet.
    • Craig McNally will communicate this recommendation to the Capacity Planning group, and possibly Oleksii Petrenko.
    • Additional communication will be made once the path forward is clear.

5 min

Update on

Jira Legacy
serverSystem JiraJIRA
serverId01505d01-b853-3c2e-90f1-ee9b165564fc
keyFOLIO-3317
 

Axel
  • Axel Dörrer Should be removed from week to week agenda and Axel will monitor for progress and report back
  • MDEXP-487 has been verified and moved to an fixed version
  • MODEUS-139 has been moved to the next sprint

Today:

  • Axel Dörrer  will discuss the data-import ticket with Ann-Marie B. after Lotus.
5-10 min

Jira Legacy
serverSystem JiraJIRA
serverId01505d01-b853-3c2e-90f1-ee9b165564fc
keyRMB-902

Jira Legacy
serverSystem JiraJIRA
serverId01505d01-b853-3c2e-90f1-ee9b165564fc
keyOKAPI-1081

Team

Notes from previous weeks:

Discussions are ongoing, currently blocked on a decision being made.

  • Document the options on the wiki to facilitate these discussions and the decision making process.
  • By this group?  By the TC?
  • How do we constrain the module names?  If so, where/how?
    • Various restrictions:  Postgres, Hosting infrastructure (Kubernetes/ECS/etc.)
  • What about the tenantId restrictions?
    • Also part of the above discussion/decision.

Today:

  • Deferred again.  Check in on  
5-10 min

Jira Legacy
serverSystem JiraJIRA
serverId01505d01-b853-3c2e-90f1-ee9b165564fc
keySTCLI-190

Team

Notes from previous weeks:

There's a PR that hasn't' moved in a while... What's the status?  How do we move this forward?

Was there another PR against stripes-testing?


Today:

  • No updates - Latest update is that Ryan and Zak are still working on retesting this.
5 min

Jira Legacy
serverSystem JiraJIRA
serverId01505d01-b853-3c2e-90f1-ee9b165564fc
keyMODAT-68

Team

The ask is to review this story, and more specifically the comment thread.  We can discuss more next week.  The goal is twofold:

  1. Awareness of what's being proposed
  2. Possibly make recommendations to the CP team if we have strong feelings about the direction the project goes with this.

*

Review the Kanban boardTeam

Ryan Berger to bring up the react-hot-loader dependency at stripes architecture - is it possible to move this dependency to a central location?

Marking all un-reviewed react-hot-loader tickets as P3 / security-reviewed.  Thank you Julian Ladisch for creating all of these!

Action items

  •  Julian Ladisch to document the options for restricting tenantId and module names on the wiki (Context:
    Jira Legacy
    serverSystem JiraJIRA
    serverId01505d01-b853-3c2e-90f1-ee9b165564fc
    keyRMB-902
    /
    Jira Legacy
    serverSystem JiraJIRA
    serverId01505d01-b853-3c2e-90f1-ee9b165564fc
    keyOKAPI-1081
    )