2023-09-21 Meeting notes
Date
Sep 21, 2023
Attendees
Name | Present |
|---|---|
@Craig McNally | Y |
@Julian Ladisch |
|
@Axel Dörrer | Y |
@Ryan Berger | Y |
@Chris Rutledge | Y |
@Jakub Skoczen | Y |
@John Coburn | Y |
@Skott Klebe |
|
@Jens Heinrich | Y |
Discussion items
Time | Item | Who | Notes |
|---|---|---|---|
| Anything Urgent? Review the Kanban board? | Team |
|
| NCT Group pen testing works and overlaps with the ZAP testing | Axel @Jens Heinrich | We've asked the NCT group if someone could join us to discuss the pen testing they're doing, how it overlaps with the ZAP testing, etc. Let's aim for Sep 21, 2023. @Axel Dörrer will coordinate with the NCT group to set this up, forward invites, etc. Notes:
|
| RSRVR-125 "Cross-site Scripting (XSS) in webroot/index.js" | Julian/Jakub | @Jakub Skoczen will get it addressed soon, it's mostly a bandwidth issue Suggestion was to drop Reservoir from the security board (possibly snyk too) since it isn't part of the Folio flower releases |
| Consortia Tenant Checks |
| How can the consortia token security issues been addressed?
|
|
|
|
|
Action items