2022-04-07 Meeting notes

2022-04-07 Meeting notes

Date

Apr 7, 2022

Attendees

  • @Craig McNally 

  • @Ryan Berger (Deactivated) 

  • @Julian Ladisch 

  • @Chris Rutledge 

  • @Axel Dörrer 

Discussion items

Time

Item

Who

Notes

Time

Item

Who

Notes

5-10 min

Spring RCE vulnerability

All

See https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement


Today:

  • @Julian Ladisch has created a few JIRAs for this – he's still working on this.

  • He also wrote a script to list the affected modules - runs periodically

  • The edge modules are probably the most critical - 3 of them are affected.  The related POs are aware.

  • Should these fixes be backported to Kiwi?

    • Prevailing thought is that it should since Kiwi is the latest release and Lotus isn't official yet.

    • @Craig McNally will communicate this recommendation to the Capacity Planning group, and possibly Oleksii Petrenko.

    • Additional communication will be made once the path forward is clear.

5 min

Update on https://folio-org.atlassian.net/browse/FOLIO-3317 

Axel

  • @Axel Dörrer Should be removed from week to week agenda and Axel will monitor for progress and report back

  • MDEXP-487 has been verified and moved to an fixed version

  • MODEUS-139 has been moved to the next sprint


Today:

  • @Axel Dörrer  will discuss the data-import ticket with Ann-Marie B. after Lotus.

5-10 min

https://folio-org.atlassian.net/browse/RMB-902

https://folio-org.atlassian.net/browse/OKAPI-1081

Team

Notes from previous weeks:

Discussions are ongoing, currently blocked on a decision being made.

  • Document the options on the wiki to facilitate these discussions and the decision making process.

    • @Julian Ladisch to take this on.

  • By this group?  By the TC?

  • How do we constrain the module names?  If so, where/how?

    • Various restrictions:  Postgres, Hosting infrastructure (Kubernetes/ECS/etc.)

  • What about the tenantId restrictions?

    • Also part of the above discussion/decision.


Today:

  • Deferred again.  Check in on Apr 14, 2022 

5-10 min

https://folio-org.atlassian.net/browse/STCLI-190

Team

Notes from previous weeks:

There's a PR that hasn't' moved in a while... What's the status?  How do we move this forward?

  • @Ryan Berger (Deactivated) / @John Coburn to help push this along.

Was there another PR against stripes-testing?


Today:

  • No updates - Latest update is that Ryan and Zak are still working on retesting this.

5 min

https://folio-org.atlassian.net/browse/MODAT-68

Team

The ask is to review this story, and more specifically the comment thread.  We can discuss more next week.  The goal is twofold:

  1. Awareness of what's being proposed

  2. Possibly make recommendations to the CP team if we have strong feelings about the direction the project goes with this.

*

Review the Kanban board

Team

@Ryan Berger (Deactivated) to bring up the react-hot-loader dependency at stripes architecture - is it possible to move this dependency to a central location?

Marking all un-reviewed react-hot-loader tickets as P3 / security-reviewed.  Thank you @Julian Ladisch for creating all of these!

Action items

@Julian Ladisch to document the options for restricting tenantId and module names on the wiki (Context:https://folio-org.atlassian.net/browse/RMB-902/https://folio-org.atlassian.net/browse/OKAPI-1081)