June 12, 2023 Meeting

Attendees:

 

Agenda Item

 Notes

Owner

Actions / Next Steps

Agenda Item

 Notes

Owner

Actions / Next Steps

Updates on Release 1.9

  • #15164: td-agent version pinning

  • #15161 might take more time as the flows are generated during bazel (update from Devops team).

Sikander-Wavelabs

 

Lucas reached out to yogesh, for C++ changes and new feature changes to look into security POV for 1.9, still blocked on CI/CD dashboard

  • sikander will update ticket with details

  • Yogesh catch up with features group to pick release date

  • Jordan - propose mid august for 1.9 release date

  • Lucas - can we address ci/cd dashboard and not have wavelabs block.

  • Jordan - have technical meeting just for CI/CD dashboard issue that is blocking 1.9, yogesh please explain difficulties, 

    • Will use this weeks eng meeting for the above

  • Max - has not been a pr since 2nd may  

Bug Bounty Program

  • Hackerone agreement is signed!

  • Lucas proposed "refactor reviewdog-workflow.yml for security" https://github.com/magma/security/issues/147

  • Som proposed windowing scheme

  • The Security WG discussed disclosure of security weakness in bounties for fixing them.

 

 

  • Hackerone customer service will be reaching out to onboard us.

  • Arrived on policy for disclosing security issues: ok to disclose if trivial, otherwise we will reserve bug bounties for trusted contributors.

  • Refactoring reviewdog-workflow.yml approved. Lucas to move the issue from the security repo to the public repo. (https://github.com/magma/magma/issues/15192)

  • Bounty amounts need to be defined

  • Shubham to document two bounty proposals: upgrade Kubernetes; create CI job to scan Docker images for vulnerabilities using trivy

  • Som to create a page in the LF wiki on the bounty program.

  • Need draft Quickstart for anyone who wants to recommend a bug bounty program (process & timeline) - Jordan will start doc, Ben add in budget info. Bounty Program Process
    [ NEED TO CLOSE THIS - TSC members please review/comment]

  • Ben - add paragraph on how payments will work

  • Folks will review and comment this week

Outreach Report

@Som Sikdar 

  • Action items and next steps are captured in document

  •  Pick topics and date for next town hall

  • Bevy page is live. Can tweak description, presenters as needed.

Other:

  • eBPF 

General discussion on interest in eBPF project (migration from OVS)

@Pravin Shelar

  • @Shubham Tatvamasi , Suresh (Wavelabs), Som are interested
    @pbshelar@fb.com will start the document. Contact him over slack if you are interested in participating.

Community contribution: service conf script

Javier Aubert has created a script*
 for getting all services running. Let's discuss how to move it forward.

@Lucas Gonze 

  • reframe as docusaurus

  • generally complete. remove from future agenda

  • lucas & javier - add a short write up to wiki

What's Next For Magma

@Jordan Vrtanoski 

  • Quick overview of the message to be sent on the town-hall meeting

AWS Credits

Can @Ben Sternthal be granted access as billing manager to our AWS account? I'd like to see if we can get AWS credits for our account (will apply in december). Also would need a contact for help on an estimate

@Ben Sternthal 

  • Shubham might be aws contact. Ben will reach out.

Holiday June 19th

Suggest rescheduling to Tuesday or Wed

@Ben Sternthal 

  • yep move to tuesday

Demo

Raul Flamenco says "On our end, we have a small number of students still interested on a demo.  Any suggestions on who to contact?"

@Lucas Gonze 

Let's discuss how to make the time for evangelism.

  • Jordan has demo, will circle up after this weeks town hall

Review Latest Q&A In Github, Review Slack For Candidate Github Topics

 

@Lucas Gonze 

 

Recording:

https://zoom.us/rec/share/__4tOZhET6AGdAUR2wNKEqGPqZPEE_5Wx3TRwD2fIUr5tkYsbYBwoMDJhrg_ZxlX.zM3AL27vGmN4hiDE