2025-01-23 Meeting notes
Date
Jan 23, 2025
Attendees
Name | Present | Planned Absences |
|---|---|---|
@Craig McNally | Yes |
|
@Julian Ladisch | Yes | 2025-01-30 |
@Axel Dörrer |
|
|
@Ryan Berger | Yes |
|
@Chris Rutledge | Yes |
|
@Jakub Skoczen |
|
|
@John Coburn | Yes |
|
@Skott Klebe |
|
|
@Kevin Day | Yes |
|
@Jens Heinrich | Yes |
|
@Tom Gorman (Guest) | Yes |
|
Discussion items
Time | Item | Who | Notes |
|---|---|---|---|
10-15 min | Tom Gorman introduction | @Tom Gorman | Tom Gorman, a security expert at EBSCO has expressed interest in joining the Security Team. This is an opportunity to familiarize ourselves with his background, get aligned on expectations, etc.
|
<5 min | Issue tagging idea | @Jens Heinrich | Idea: Have a Tag
Last week:
Today:
|
0 min | Jira Group and Security Level review | Team | From Craig in slack:
Today:
|
5 min | Policy for deprecating and eventually removing unsupported code | Team | The idea is to draft a proposal policy for this and run it by the TC for approval... "mod-foo has known security vulnerabilities which are high/critical and have not been addressed in N months. If these aren't addressed within N months the repository will be archived" Something like that...
@Jens Heinrich created a draft and @Julian Ladisch gave inputs on better handling of edge cases A dedicated page has been created at https://folio-org.atlassian.net/wiki/x/KAAHJw
Today:
|
* | Anything Urgent? Under Review Filter: | Team |
|
Topic Backlog | |||
Time permitting | Advice for handling of sensitive banking information | Team | From slack conversation, I think I've gathered the following:
Let's review and discuss before providing this feedback to Raman. @Axel Dörrer also suggested that defining classes of sensitivity could help teams determine which techniques are applicable in various situations. I agree having some general guidelines on this would be helpful.
It would probably help to provide concrete examples of data in each class. This can be a longer term effort, we don't need to sort out all the details today.
Today: @Axel Dörrer to do a first draft as a base for further discussions |
| Status on pentesting works within Network traffic control group | @Axel Dörrer | Due to some absences on different reasons the group stalled. Axel will try to reactivate the group. |
| Okapi Debian Package https://folio-org.atlassian.net/browse/FOLIO-3896 |
|
|
Action items