2022-04-07 Meeting notes

Date

Attendees

Discussion items

TimeItemWhoNotes
5-10 minSpring RCE vulnerabilityAll

Today:

  • Julian Ladisch has created a few JIRAs for this – he's still working on this.
  • He also wrote a script to list the affected modules - runs periodically
  • The edge modules are probably the most critical - 3 of them are affected.  The related POs are aware.
  • Should these fixes be backported to Kiwi?
    • Prevailing thought is that it should since Kiwi is the latest release and Lotus isn't official yet.
    • Craig McNally will communicate this recommendation to the Capacity Planning group, and possibly Oleksii Petrenko.
    • Additional communication will be made once the path forward is clear.

5 min

Update on FOLIO-3317 - Getting issue details... STATUS  

Axel
  • Axel Dörrer Should be removed from week to week agenda and Axel will monitor for progress and report back
  • MDEXP-487 has been verified and moved to an fixed version
  • MODEUS-139 has been moved to the next sprint

Today:

  • Axel Dörrer  will discuss the data-import ticket with Ann-Marie B. after Lotus.
5-10 min

RMB-902 - Getting issue details... STATUS

OKAPI-1081 - Getting issue details... STATUS

Team

Notes from previous weeks:

Discussions are ongoing, currently blocked on a decision being made.

  • Document the options on the wiki to facilitate these discussions and the decision making process.
  • By this group?  By the TC?
  • How do we constrain the module names?  If so, where/how?
    • Various restrictions:  Postgres, Hosting infrastructure (Kubernetes/ECS/etc.)
  • What about the tenantId restrictions?
    • Also part of the above discussion/decision.

Today:

  • Deferred again.  Check in on  
5-10 min

STCLI-190 - Getting issue details... STATUS

Team

Notes from previous weeks:

There's a PR that hasn't' moved in a while... What's the status?  How do we move this forward?

Was there another PR against stripes-testing?


Today:

  • No updates - Latest update is that Ryan and Zak are still working on retesting this.
5 min

MODAT-68 - Getting issue details... STATUS

Team

The ask is to review this story, and more specifically the comment thread.  We can discuss more next week.  The goal is twofold:

  1. Awareness of what's being proposed
  2. Possibly make recommendations to the CP team if we have strong feelings about the direction the project goes with this.

*

Review the Kanban boardTeam

Ryan Berger to bring up the react-hot-loader dependency at stripes architecture - is it possible to move this dependency to a central location?

Marking all un-reviewed react-hot-loader tickets as P3 / security-reviewed.  Thank you Julian Ladisch for creating all of these!

Action items

  • Julian Ladisch to document the options for restricting tenantId and module names on the wiki (Context: RMB-902 - Getting issue details... STATUS / OKAPI-1081 - Getting issue details... STATUS )