Skip to end of banner
Go to start of banner

2022-05-19 Meeting notes

Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 3 Next »

Date

Attendees

Discussion items

NOTE: Detailed notes weren't captured for today's meeting.  For the most part the time was spent reviewing the Kanban board.  We left comments on several JIRAs, but nothing worth explicitly noting here.

TimeItemWhoNotes
5-10 minSpring RCE vulnerabilityAll

See https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement

  • FOLSPRINGB-47 - Getting issue details... STATUS
  • Julian Ladisch is writing a script to check for vulnerable modules
  • A message/update was posted to #sys-ops:  https://folio-project.slack.com/archives/C9BBWRCNB/p1648740057373649?thread_ts=1648728230.119219&cid=C9BBWRCNB
  • Julian Ladisch has created a few JIRAs for this – he's still working on this.
  • He also wrote a script to list the affected modules - runs periodically
  • The edge modules are probably the most critical - 3 of them are affected.  The related POs are aware.
  • Should these fixes be backported to Kiwi?
    • Prevailing thought is that it should since Kiwi is the latest release and Lotus isn't official yet.
    • Craig McNally will communicate this recommendation to the Capacity Planning group, and possibly Oleksii Petrenko.
    • Additional communication will be made once the path forward is clear.
  • Discussed with Mark V. Harry K, and Oleksii P. - Aiming for Lotus (HF) and Morning Glory.
  • Still confusion about how many releases need to be supported, LTS, etc. 
  • Note that this is a P3, if it were a P1/P2 the decision might have been different.
  • The priority for some of these stories (specifically edge APIs and the umbrella story) has been bumped to P2
    • This was done so that the fixes can be included in a Lotus hot fix

Today:


Official security support policy on releases

Security team needs

  • How many releases from now has to be supported? (3-4 releases or less?)
  • Priority/Risk will likely factor into this as well.
  • Also a matter of capacity
  • Should be raised to the PC → Axel can bring this with a paper/proposal to the PC - not yet.
  • Probably want to bring this to the TC as well at some point, even if only for awareness.
  • WOLFcon session?
  • Axel will produce a paper that outlines that problem by next weeks meeting.
  • Chris to ask his stakeholders about TAMU needs - not specifically, but has started to have some conversations
  • https://docs.google.com/document/d/1Un5OlutEh7M2p3AzxE8g20NmdeEhrC0KCNkfd_QLkRw
  • Continue discussion from slack... Spring Boot LTS 
  • We need to communicate the expectation better - e.g. add something to the platform release notes indicate how long P1 security issues will be backported to that release.
  • As long as we upgrade to the latest LTS release of Spring Boot in each flower release, we should be in decent shape - only ~1 mo. where we're running a version of Spring boot that's no longer supported.
  • Note that we're currently a bit behind with this, even if we upgrade edge modules, etc. in a Lotus HF, kiwi and Juniper will be running older, unsupported versions for some period of time.  Going forward we'll need to be diligent about this to avoid getting into this situation again.

Today:

5 min

Update on FOLIO-3317 - Getting issue details... STATUS  

Axel
  • Axel Dörrer Should be removed from week to week agenda and Axel will monitor for progress and report back
  • MODEUS-139 has been moved to the next sprint
  • Axel Dörrer  waiting to hear back from Ann-Marie B. about the data-import ticket ... maybe target Nolana?

Today:

5-10 min

RMB-902 - Getting issue details... STATUS

OKAPI-1081 - Getting issue details... STATUS

Team

Notes from previous weeks:

Discussions are ongoing, currently blocked on a decision being made.

  • Document the options on the wiki to facilitate these discussions and the decision making process.
  • By this group?  By the TC?
  • How do we constrain the module names?  If so, where/how?
    • Various restrictions:  Postgres, Hosting infrastructure (Kubernetes/ECS/etc.)
  • What about the tenantId restrictions?
    • Also part of the above discussion/decision.
  • Some design choices have been suggested.
  • Julian Ladisch to raise awareness of Tenant Id and Module Name Restrictions via posting to #sys-ops and #development slack channels

Today:

  • Check in on progress of this.
5-10 min

STCLI-190 - Getting issue details... STATUS

Team

Notes from previous weeks:

There's a PR that hasn't' moved in a while... What's the status?  How do we move this forward?

Was there another PR against stripes-testing?

  • ui-test:94 Was merged, a problem was reported, leading to this being reverted.
  • Appears to be an environmental problem.  
  • The JIRA is now unassigned... it isn't clear who has the ball here.
  • Added a comment to STCLI-190 tagging Khalilah, Ryan, and Zak
  • This PR has been reverted because of issues with the included changes of kopy version. The idea is to exclude the kopy changes by now to move forward with this.
  • Last week:  
    • No movement, but a PR should be coming soon.
  • Conversations are ongoing within the Stripes Arch. group.
  • Maybe replace kopy with something else that's better maintained
  • Maybe roll our own replacement

Today:

5-10 min

MSEARCH-357 - Getting issue details... STATUS

Teamhave we heard anything from the mod-search devs on this?  Is it possible to use the openSearch client, or possibly make it configurable which client is used?  

*

Review the Kanban boardTeam


Action items


  • No labels