@@ -19,23 +19,23 @@ title: CPANSec bi-weekly minutes
1919
2020- @stigtsp
2121 - CVE workflow
22- - working on alternative workflow tools for CVE based on YAML
23- - easier to use than Vulnogram
24- - possible bulk updates
22+ - Working on alternative workflow tools for CVE based on YAML that is easier to use than Vulnogram
23+ - Allows possible bulk updates
2524
2625 - @sjn @robrwo
27- - questions about posting links to CVEs in Mastodon, BlueSky etc.
28- - there is no RSS available for the CVE announcement list
26+ - Questions about posting links to CVEs in Mastodon, BlueSky etc.
27+ - There is no RSS available for the CVE announcement list
2928 - @sjn suggests a custom emitter that produces content suitable for manual cut&paste (max 280 chars) for now. API auto-posting can come later
3029
3130 - @timlegge
32- - a copy of published CVEs should be kept in a public git repo
33- - this should be a file copy, not clone of CNA repo, with sanity checks to ensure CVEs public
34- - but MITRE has a public git repo
31+ - Suggests that a copy of published CVEs should be kept in a public git repo
32+ - This should be a file copy, not clone of CNA repo, with sanity checks to ensure CVEs public
33+ - @robrwo notes that we host patches from CNA repo on CPANSec website, and could host CVEs there as well
34+ - @stigtsp MITRE has a public git repo, so this may be unnecessary
3535
3636 - @robrwo
37- - working on CVE Workflow documentation
38- - CVE "style guide" thaat could be incorporated into @stigtsp 's cna tool
37+ - Working on CVE Workflow documentation
38+ - CVE "style guide" that could be incorporated into @stigtsp 's cna tool
3939
4040- @timlegge
4141 - OpenSSF Vulnerability Disclosure WG
@@ -50,38 +50,38 @@ title: CPANSec bi-weekly minutes
5050 - Details omitted from agenda.
5151
5252 - @sjn
53- - suggested improving vulnerability disclosure process with time, phases and well-publiched steps.
53+ - Suggested improving vulnerability disclosure process with time, phases and well-publiched steps.
5454
5555 - @robrwo
56- - experimental triage repo unused, should be deleted @stiptsp
57- - give triage list members access to the CNA repo, and use that for issue tracking
58- - create a kanban
56+ - Experimental triage repo unused, should be deleted @stiptsp
57+ - Give triage list members access to the CNA repo, and use that for issue tracking
58+ - Create a kanban
5959
6060- @sjn
6161 - Perl Toolchain Summit (PTS)
62- - focusing on EU Cyber Resiliance Act (CRA) steward organisation
63- - need to decide what the org looks like and set it up so it can be formally created
62+ - Focusing on EU Cyber Resiliance Act (CRA) steward organisation
63+ - Need to decide what the org looks like and set it up so it can be formally created
6464 - CPANSec would be a member, but separate from the stweard org
6565 - We have funding (via TPRF's budget) that we can choose to use to help fund a third room at PTS
6666 - we have to get the EU CRA to work for CPAN, we * have* to update the META spec to fully update the dependency graph.
6767 - @sjn calls for volunteers! This is critically important.
6868
6969- @stigtsp
7070 - CPAN pURLs
71- - spec does not support selector use case we need for CVEs (author/version constraints)
72- - work in process
71+ - Spec does not support selector use case we need for CVEs (author/version constraints)
72+ - Work in process
7373 - @sjn calls for volunteers to finish the work ASAP.
7474
7575- @sjn
7676 - TPRF funding
7777 - @stiptsp
78- - suggestion for sending message to the mailing list with a short budget
78+ - Suggestion for sending message to the mailing list with a short budget
7979 - Goal: put together a formal decision-making process for CPANSec
8080
8181- @robrwo
82- - we need tools for accessing community documentation (license, security policy, etc)
83- - meta spec/tools for downloading and showing these documents
84- - possible PTS project
82+ - We need tools for accessing community documentation (license, security policy, etc)
83+ - Meta spec/tools for downloading and showing these documents
84+ - Possible PTS project
8585
8686- @stigstp
87- - demo of cna tool https://github.com/CPAN-Security/cna-tool
87+ - Demo of ` cna ` tool https://github.com/CPAN-Security/cna-tool
0 commit comments