From f83eac2ba647967fce71a47edbf3cfee1bad127b Mon Sep 17 00:00:00 2001 From: Tristan Cacqueray Date: Wed, 15 May 2024 16:23:46 -0400 Subject: [PATCH] meeting notes: 2024-05-15 --- meeting-notes/2024-05-15.md | 22 ++++++++++++++++++++++ 1 file changed, 22 insertions(+) create mode 100644 meeting-notes/2024-05-15.md diff --git a/meeting-notes/2024-05-15.md b/meeting-notes/2024-05-15.md new file mode 100644 index 00000000..48f2fb56 --- /dev/null +++ b/meeting-notes/2024-05-15.md @@ -0,0 +1,22 @@ +# SRT meeting 2024-05-15 + +Previous notes: +https://github.com/haskell/security-advisories/blob/main/meeting-notes/2024-05-01.md + +## Cabal plan integration + +- A new cabal-audit project consuming the security-avisories is now being worked on https://github.com/mangoiv/cabal-audit + +## CI Security Advice Update + +- Shared on [discourse]( https://discourse.haskell.org/t/how-to-secure-github-repositories/9478) +- Updated the guide based on feedback [PR#193](https://github.com/haskell/security-advisories/pull/193) + +## Hackage Auth + +- Discussed with hackage team to improve the authentication scheme. + +## Dependencies analysis + +- Investigated getting in touch with deps.dev to increase audit coverage. +- Also considering dependabot support for cabal dependencies.