Skip to content

Commit 8995bfe

Browse files
authored
Merge pull request #54 from jupyter/notes-2023-01
Notes from late January
2 parents aff4d47 + 2f1a6f1 commit 8995bfe

File tree

3 files changed

+65
-0
lines changed

3 files changed

+65
-0
lines changed

meetings/2023-01-17.md

Lines changed: 36 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,36 @@
1+
## January 17, 2023
2+
3+
| Name | affiliation| username |
4+
| -------------------| -----------| -----------------|
5+
| Jason Weill | AWS | @JasonWeill |
6+
| Matthias Bussonnier| Quansight | @carreau |
7+
| Rollin Thomas | NERSC | @rcthomas |
8+
| Jason Grout | Databricks | @jasongrout |
9+
10+
- Security email addresses
11+
- [email protected] — Google Group, limited membership.
12+
- This is a limited-membership list, if someone ask to be put on it, we do a cursory check they are a real person and add them it is mostly meant for advance warning we are going to publish a release that fix a CVE and minor sec discussion.
13+
- 75 members now
14+
15+
- This is a forward email maintained by XXXX, that only allow up to 10 members, it is meant for security reports.
16+
- Action items:
17+
- Formalize policy around who gets on these lists
18+
- Maybe set up new [email protected] reporting email?
19+
- widen the [email protected] receivers to spread the load
20+
21+
- Bug bounty recommendation (intigrity, etc)
22+
- Jupyter as a software may not be a good fit for Intigrity. What Intigrity is offering is that if you have a service you sell with an API, we ask our researchers to pentest your service. If it's software that you install on your machine, it doesn't really fit the Intigriti model, which seems to
23+
- What services do we actually run?
24+
- nbviewer - no authentication, purely displays content, so not really applicable
25+
- binder
26+
- A difficulty is that some people we are talking with are in the European Union, others are from Intigriti
27+
- Action item:
28+
- Jason G to email Intigriti, to confirm whether this is a good fit, based on previous conversations
29+
- If it is a good fit, Jason G to email SSC to see what subprojects are interested, then forward that on to Intigriti
30+
31+
- Recent reports
32+
- How do we manage security reports coming in?
33+
- Several options:
34+
- Security reports per subproject
35+
- Security reports in a centralized Project Jupyter repo
36+
- Security reports in a repo per subproject

meetings/2023-01-31.md

Lines changed: 27 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,27 @@
1+
## January 31, 2023
2+
3+
| Name | affiliation| username |
4+
| -------------------| -----------| -----------------|
5+
| Rick Wagner | UCSD | @rpwagner |
6+
| A. T. Darian | QuantStack | @afshin |
7+
| Sritej Attaluri | Bloomberg | @attaluris |
8+
| Piyush Jain | AWS | @3coins |
9+
| Rollin Thomas | NERSC | @rcthomas |
10+
| Joe Lucas | NVIDIA | @josephtlucas |
11+
12+
* EC and SSC meeting this Friday
13+
* Conversation with TrustedCI / Workshop in October
14+
* Rollin and Rick will talk to TrustedCI about scope, logistics, etc
15+
* There may be good reasons for Jupyter community members to attend TrustedCI summit generally
16+
* Software supply chain affects everyone
17+
* Security affects everyone
18+
* Hello Joe Lucas
19+
* A JupyterLab extension to evaluate the security of your Jupyter environment
20+
* https://github.com/JosephTLucas/jupysec
21+
* Bug bounty program questions for discussion
22+
* jupyterlab, jupyterlab-server and jupyter-server proposed so far w/contacts for each
23+
* Jason G. proposed to use the Github CVE process for reporting bugs. Is this the process that should be followed by the Intigriti Team/Bug reporters?
24+
* Is any one familiar with Intigriti?
25+
* Should we have security.jupyter.org (or sec.jupyter.org)?
26+
* Hub is moving forward on hub.jupyter.org as precedent
27+
* https://github.com/jupyterhub/team-compass/issues/444

meetings/README.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -17,6 +17,8 @@ What this meeting is about:
1717

1818
## Meeting Minutes
1919

20+
* [2023-01-31](2023-01-31.md)
21+
* [2023-01-17](2023-01-17.md)
2022
* [2023-01-03](2023-01-03.md)
2123
* [2022-12-06](2022-12-06.md)
2224
* [2022-10-11](2022-10-11.md)

0 commit comments

Comments
 (0)