Skip to content

Commit 11a8170

Browse files
frasertweedaleblackheaven
authored andcommitted
meeting-notes: 2025-07-10
1 parent b7e3663 commit 11a8170

File tree

1 file changed

+62
-0
lines changed

1 file changed

+62
-0
lines changed

meeting-notes/2025-07-10.md

Lines changed: 62 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,62 @@
1+
# SRT meeting 2025-07-10
2+
3+
Previously:
4+
https://github.com/haskell/security-advisories/blob/main/meeting-notes/2025-06-25.md
5+
6+
7+
## Q2 report topics
8+
9+
- ZuriHac report (Tristan will write the section)
10+
- 1 new advisory (a couple in early April were accounted in Q1 report)
11+
- The web index not-vulnerability report :)
12+
- OCaml security team shout-out (see below)
13+
14+
15+
## Security work "prospectus"
16+
17+
Following informal conversation with Jose at ZuriHac, it is time to
18+
pull this together. Gather all the high-impact ideas (which are
19+
currently scattered across meeting notes, issues, etc) into a
20+
"prospectus" document which may help with funding decisions.
21+
22+
23+
## Hackage key signing
24+
25+
> We’re looking for more people to take part in the hackage key signing
26+
> ceremony. I figured it would be useful to have someone from the security
27+
> response team be part of that trusted group. Is this something you’d be
28+
> willing to do? It would require you to take part of the ceremony in the
29+
> next few weeks, But it can all be done online.
30+
31+
FT will circle back with Jose and find out next steps.
32+
33+
34+
## OCaml security team
35+
36+
OCSF is starting a security team. Richard Eisenberg reached out to
37+
FT to ask for advice. FT will share some resources.
38+
39+
40+
## Embaroged advisory process
41+
42+
Tristan feels our current *ad hoc* system using the mailing list
43+
could be improved. Tristan will investigate and make
44+
recommendations on what we could implement to improve the processes.
45+
46+
47+
## Purl library
48+
49+
Consensus: merge and publish without delay. Gautier will do the
50+
Hackage publishing.
51+
52+
53+
## SRT processes documentation
54+
55+
FT realised that we need to include the hackage package
56+
maintainership in the checklists. So he will fix that :)
57+
58+
59+
## Next SRT meeting
60+
61+
It is the summer holidays (north of the Equator). Skip it
62+
for all?

0 commit comments

Comments
 (0)