Thanks to everyone who attended the Security SIG BoF session!

Attached are the notes taken from the discussion during the session with relevant links.  If there was anything missed, please feel free to mention it here or reach out in #openstack-security.


Topics:
  • Overall Security SIG
  • Links:
  • Meeting Time: Weekly on Thursday at 1500 UTC #openstack-meeting
  • Running bandit as part of tox gate
  • Run as a separate job
  • Host Intrusion 
  • Ansible Hardening
  • Security SIG "Help Wanted"
  • Only has Barbican, missing other projects that have been added since
  • Multiple other libraries in review to be added
  • Security guide doesn’t seem to have been updated since Pike, so it’s a good 1.5 years behind
  • Improve documentation of secure coding practices
  • improve coverage of bandit and syntribos jobs across projects, and look into other similar tools we could be using to better secure the software we write
  • Help with writing security notes and triaging the backlog
  • VMT Public Bug Assistance
  • Many reports of suspected vulnerabilities start out as public bugs or are made public over the course of being triaged, and assistance with those is encouraged from the entire community
  • Having someone who is familiar with the affected project provide context to a security bug really helps the VMT definine concrete impact statements and speeds up the overall process
  • Bootstrapping AWS / Windows Guest Domains / Guest VMs
  • Policy
  • Cross-project policy effort: