17. January 2023 #1115
dimakuv
started this conversation in
Meeting notes
Replies: 1 comment
-
Benny: Current status of docu restructuring |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Agenda
(please write your proposed agenda items in comments under this discussion)
gramine-sgx-sign
plugin architecture.Opens
Mona: we should ask Don about whether he wants to reschedule the meeting, so he can attend.
Woju: tracking vulnerabilities in upstream projects
Woju: stumbled upon a security issue in mbedTLS. Is there any security process how we track/receive notifications from our upstream projects that Gramine is dependent upon? Until now, it was ad-hoc.
Sankar: before every Gramine release, we run some tool (at Intel) to verify there are no known vulnerabilities in the dependencies.
We can increase the frequency of this scan.
Woju: what does this scan do exactly?
Michal: propose to do a minor release after few days when we patch/fix vulnerabilities.
Woju: what is the exact process we follow when we find out about such security vulnerabilities?
TODOs:
Mona: Public list of what's included in the next release
Mona: there is no public list of what goes into the upcoming release (or just generally, what is the plan and priorities for Gramine features, i.e. there is no Gramine roadmap).
TODOs:
Woju:
gramine-sgx-sign
plugin architectureWoju: there is a PR with a complicated way of having signing plugins in GSC (by supplying Dockerfile templates).
[ Woju schreenshares how his proposed plugin arch works ]
See #1118.
TODOs:
Beta Was this translation helpful? Give feedback.
All reactions