2022-03-31 Meeting notes

2022-03-31 Meeting notes

Date

Mar 31, 2022

Attendees

  • @Chris Rutledge 

  • @Craig McNally 

  • @Julian Ladisch 

  • @Ryan Berger (Deactivated) 

  • @Jakub Skoczen 

Discussion items

Time

Item

Who

Notes

Time

Item

Who

Notes

20 min

Spring RCE vulnerability

All

See https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement

5 min

Update on https://folio-org.atlassian.net/browse/FOLIO-3317 

Axel

  • @Axel Dörrer Should be removed from week to week agenda and Axel will monitor for progress and report back

  • MDEXP-487 has been verified and moved to an fixed version

  • MODEUS-139 has been moved to the next sprint


Today:

  • Deferred since Axel is not  here.

5-10 min

https://folio-org.atlassian.net/browse/RMB-902

https://folio-org.atlassian.net/browse/OKAPI-1081

Team

Notes from previous week:

Discussions are ongoing, currently blocked on a decision being made.

  • Document the options on the wiki to facilitate these discussions and the decision making process.

    • @Julian Ladisch to take this on.

  • By this group?  By the TC?

  • How do we constrain the module names?  If so, where/how?

    • Various restrictions:  Postgres, Hosting infrastructure (Kubernetes/ECS/etc.)

  • What about the tenantId restrictions?

    • Also part of the above discussion/decision.


Today:

  • Deferred.  Further discussion once Julian finalizes the proposal, next week

5-10 min

https://folio-org.atlassian.net/browse/STCLI-190

Team

Notes from previous week:

There's a PR that hasn't' moved in a while... What's the status?  How do we move this forward?

  • @Ryan Berger (Deactivated) / @John Coburn to help push this along.

Was there another PR against stripes-testing?


Today:

  • Ryan and Zak are still working on retesting this, we'll check back next week

*

Review the Kanban board

Team

We stayed late and reviewed a bunch of stories.

There are a bunch related to stripes-hot-loader which we deferred for now.  We'll need to get to them at some point, but focused on the other issues today.

Action items

@Julian Ladisch to document the options for restricting tenantId and module names on the wiki (Context:https://folio-org.atlassian.net/browse/RMB-902/https://folio-org.atlassian.net/browse/OKAPI-1081)