2022-05-05 Meeting notes

2022-05-05 Meeting notes

Date

May 5, 2022

Attendees

  • @Julian Ladisch 

  • @Johnmcdonald (Deactivated) 

  • @Chris Rutledge 

  • @Craig McNally 

Discussion items

NOTE: Detailed notes weren't captured for today's meeting.  For the most part the time was spent reviewing the Kanban board.  We left comments on several JIRAs, but nothing worth explicitly noting here.

Time

Item

Who

Notes

Time

Item

Who

Notes

5-10 min

Spring RCE vulnerability

All

See https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement


Today:

  • Discussed with Mark V. Harry K, and Oleksii P. - Aiming for Lotus (HF) and Morning Glory.

  • Still confusion about how many releases need to be supported, LTS, etc. 

  • Note that this is a P3, if it were a P1/P2 the decision might have been different.



Official security support policy on releases



Security team needs

  • How many releases from now has to be supported? (3-4 releases or less?)

  • Priority/Risk will likely factor into this as well.

  • Also a matter of capacity

  • Should be raised to the PC → Axel can bring this with a paper/proposal to the PC - not yet.

  • Probably want to bring this to the TC as well at some point, even if only for awareness.

  • WOLFcon session?

  • Axel will produce a paper that outlines that problem by next weeks meeting.

  • Chris to ask his stakeholders about TAMU needs - not specifically, but has started to have some conversations

5 min

Update on https://folio-org.atlassian.net/browse/FOLIO-3317 

Axel

  • @Axel Dörrer Should be removed from week to week agenda and Axel will monitor for progress and report back

  • MODEUS-139 has been moved to the next sprint

  • @Axel Dörrer  waiting to hear back from Ann-Marie B. about the data-import ticket ... maybe target Nolana?


Today:

5-10 min

https://folio-org.atlassian.net/browse/RMB-902

https://folio-org.atlassian.net/browse/OKAPI-1081

Team

Notes from previous weeks:

Discussions are ongoing, currently blocked on a decision being made.

  • Document the options on the wiki to facilitate these discussions and the decision making process.

    • @Julian Ladisch to take this on.

  • By this group?  By the TC?

  • How do we constrain the module names?  If so, where/how?

    • Various restrictions:  Postgres, Hosting infrastructure (Kubernetes/ECS/etc.)

  • What about the tenantId restrictions?

    • Also part of the above discussion/decision.

  • Some design choices have been suggested.


Today:

5-10 min

https://folio-org.atlassian.net/browse/STCLI-190

Team

Notes from previous weeks:

There's a PR that hasn't' moved in a while... What's the status?  How do we move this forward?

  • @Ryan Berger / @John Coburn to help push this along.

Was there another PR against stripes-testing?

  • ui-test:94 Was merged, a problem was reported, leading to this being reverted.

  • Appears to be an environmental problem.  

  • The JIRA is now unassigned... it isn't clear who has the ball here.

  • Added a comment to STCLI-190 tagging Khalilah, Ryan, and Zak

  • This PR has been reverted because of issues with the included changes of kopy version. The idea is to exclude the kopy changes by now to move forward with this.

  • Last week:  

    • No movement, but a PR should be coming soon.


Today:

*

Review the Kanban board

Team





Action items