Skip to content

Commit

Permalink
meeting notes: 2024-01-10
Browse files Browse the repository at this point in the history
  • Loading branch information
frasertweedale authored and TristanCacqueray committed Jan 24, 2024
1 parent 6f6e6f9 commit 303bacb
Showing 1 changed file with 31 additions and 0 deletions.
31 changes: 31 additions & 0 deletions meeting-notes/2024-01-10.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
# SRT meeting 2024-01-10

Previous meeting notes: https://github.com/haskell/security-advisories/blob/main/meeting-notes/2023-12-13.md


## 2023 H2 report

- Draft sent to list; thanks for reviews. FT will publish today.

## ZuriHac plans

- We agree it's a good idea to have a project, e.g. `cabal audit`, Hackage server.
- Timeline: Jan for concept, March for concrete budget.
- Jose has contact points with cabal-install and HLS. hackage-server seems somewhat unloved.
- Maybe we prioritise getting hackage-server attention?
- Many security improvment should/could be done (e.g. 2FA)
- Can continue the discussion on list or GH issue (public).

## Oustanding PRs

- CWE library support.

## Downstream toolling

- Tristan already started something regarding tracking function calls
https://github.com/TristanCacqueray/cabal-audit
- Support to suppress false positives will be important, esp. because we have >0 advisories for *base*. This could be VEX and/or some other mechanism.

## Publishing the HTML advisory index

- Mihai: I was planning to look into the GHA but didn't get a chance yet

0 comments on commit 303bacb

Please sign in to comment.