[openstack-dev] [Security] Would people see a value in the cve-check-tool? (Reshetova, Elena)

Clint Byrum clint at fewbar.com
Wed Aug 5 16:54:52 UTC 2015


Excerpts from Reshetova, Elena's message of 2015-08-05 09:08:16 -0700:
> > The only concern that I have is the requisite database.  Downloading a
> 500MB + CVE database for the jobs could become painful.  We could either
> keep the CVE database on each node in the test pool or download it at the
> start of each cve-check job.  I¹d >be curious what the infra wizards have to
> say.
> 
> Actually the database is downloaded only once ( thefirst time) and then only
> database diffs are downloaded, which is much faster. I don't know enough
> about your node setup (do you fully clean up each node between the builds?)
> and etc., so the best way to test this would be if somebody can try it out
> and tell if it is a problem. If it is a problem, then we can discuss with
> the tool maintainer on how to address it. 
> 

Doesn't this feel like a job for AFS? Maintain the db there, and let the
nodes access it as-needed?



More information about the OpenStack-dev mailing list