2025-05-15 Meeting notes
Date
Attendees
| Name | Present | Planned Absences |
|---|---|---|
| Yes | ||
| Yes | ||
| Yes | ||
| Yes | ||
| Yes | ||
| Kevin Day | ||
| Jens Heinrich | Yes | |
| Tom Gorman | Will miss meetings on 5/8 through 5/22 |
Discussion items
| Time | Item | Who | Notes |
|---|---|---|---|
| 10 min | Extending Ramsons support period until 2026-03-31 | Julian | Extending Ramsons support period until 2026-03-31 has been proposed in Tri-Council meeting today. Secuity group suggests to not extend the support period because Spring based modules are out of support, unless all Spring base modules get updated to a supported Spring version. |
| 1 min | Bug Bounty Email | Craig McNally |
Craig has sent a response today, I came back as not deliverable. |
| 1 min | KONG-20 - Getting issue details... STATUS | Team | Should this target Sunflower CSP or Trillium? → Sunflower |
| 5-10 min | https://semgrep.dev/ | Julian Ladisch | We should give it a try - free for public repos. Julian Ladisch will reach out to Peter M. to get it setup: FOLIO-4291 - Getting issue details... STATUS |
| ? | SECURITY-272 - Getting issue details... STATUS | Team |
|
| * | Anything Urgent?
| Team |
Today:
|
| Topic Backlog | |||
| 0 min | Jira Group and Security Level review | Team | From Craig in slack:
Today:
|
| Time permitting | Advice for handling of sensitive banking information | Team | From slack conversation, I think I've gathered the following:
Let's review and discuss before providing this feedback to Raman. Axel Dörrer also suggested that defining classes of sensitivity could help teams determine which techniques are applicable in various situations. I agree having some general guidelines on this would be helpful.
It would probably help to provide concrete examples of data in each class. This can be a longer term effort, we don't need to sort out all the details today.
Today: Axel Dörrer to do a first draft as a base for further discussions |
| Status on pentesting works within Network traffic control group | Due to some absences on different reasons the group stalled. Axel will try to reactivate the group. | ||