2022-04-14 Meeting notes

2022-04-14 Meeting notes

Date

Apr 14, 2022

Attendees

  • @Craig McNally 

  • @Ryan Berger (Deactivated) 

  • @Chris Rutledge 

  • @Julian Ladisch 

Discussion items

Time

Item

Who

Notes

Time

Item

Who

Notes

5-10 min

Spring RCE vulnerability

All

See https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement


Today:

  • This conversation has started, but @Craig McNally needs to provide them with additional information about FOLIO's exposure/risk here.  WIll post an update in slack later today or tomorrow.

5 min

Update on https://folio-org.atlassian.net/browse/FOLIO-3317 

Axel

  • @Axel Dörrer Should be removed from week to week agenda and Axel will monitor for progress and report back

  • MODEUS-139 has been moved to the next sprint

  • @Axel Dörrer  will discuss the data-import ticket with Ann-Marie B. after Lotus.


Today:

  • @Axel Dörrer  is absent today - deferred until next week.

5-10 min

https://folio-org.atlassian.net/browse/RMB-902

https://folio-org.atlassian.net/browse/OKAPI-1081

Team

Notes from previous weeks:

Discussions are ongoing, currently blocked on a decision being made.

  • Document the options on the wiki to facilitate these discussions and the decision making process.

    • @Julian Ladisch to take this on.

  • By this group?  By the TC?

  • How do we constrain the module names?  If so, where/how?

    • Various restrictions:  Postgres, Hosting infrastructure (Kubernetes/ECS/etc.)

  • What about the tenantId restrictions?

    • Also part of the above discussion/decision.


Today:

  • Deferred again.  Check in on Apr 21, 2022 

5-10 min

https://folio-org.atlassian.net/browse/STCLI-190

Team

Notes from previous weeks:

There's a PR that hasn't' moved in a while... What's the status?  How do we move this forward?

  • @Ryan Berger (Deactivated) / @John Coburn to help push this along.

Was there another PR against stripes-testing?


Today:

  • Was merged, a problem was reported, leading to this being reverted.

  • Appears to be an environmental problem.  

  • The JIRA is now unassigned... it isn't clear who has the ball here.

  • Added a comment to STCLI-190 tagging Khalilah, Ryan, and Zak

10 min

https://folio-org.atlassian.net/browse/MODAT-68

Team

Context:

The ask is to review this story, and more specifically the comment thread.  We can discuss more next week.  The goal is twofold:

  1. Awareness of what's being proposed

  2. Possibly make recommendations to the CP team if we have strong feelings about the direction the project goes with this.


Today:

  • With so few people available today, it doesn't make sense to have this conversation at this time.  Revisit next week?

5 min

https://folio-org.atlassian.net/browse/RMB-907

Team/

@Julian Ladisch 

The level of exposure is not clear at this point.  @Julian Ladisch  will look into it and get back to us.  This information will feed back into conversations with capacity planning group wrt backporting to kiwi/lotus/etc.  Indications are that there will not be a Kiwi HF3, so it may be that this only gets into Lotus HF1 and Morning Glory.

*

Review the Kanban board

Team

How did this conversation go @Ryan Berger (Deactivated) ?

  • @Ryan Berger (Deactivated) to bring up the react-hot-loader dependency at stripes architecture - is it possible to move this dependency to a central location?

    • We're not using react-hotloader anymore.  A new approach is used now.  See stripes-webpack for details.

    • If someone tries to use react-hotloader, it winds up being a no-op and a recommendation is shown to use the new approach.

    • The prevailing thought is to remove this since it doesn't provide any value.

    • At this point there is no security concern here.  This is really just a technical debt issue.

 

Action items

@Julian Ladisch to document the options for restricting tenantId and module names on the wiki (Context:https://folio-org.atlassian.net/browse/RMB-902/https://folio-org.atlassian.net/browse/OKAPI-1081)