Minutes 2024-07-03
Meeting time and place
2024-07-03 17:00 UTC @ TPRF Slack #cpan-security channel
Attendees
- @sjn
- @stigtsp
- @timlegge
- @book
- @Tux
- @garu
Regrets
- @leont
Not attending
Topics
Use something else than Slack for meetings
- Something with better audio quality
- That doesn’t require invites/sign-in
This meeting was done in Element/[Matrix], which uses Jitsi. Went well.
CPANminus
- We have sent PRs to master and development
- An independent PR has been sent into the official perl-docker image.
- Trying to push for use of the new patched version
- Some argument about whether to accept into the docker images.
- @Tux mentioned the fallback is needed - an environment variable would suffice
CNA process is initiated with Mitre
- @timlegge: Mitre finally got back to me and has some information they need as well as scheduling a meeting with them to discuss
- @timlegge Stig and I are discussing
- We could use some additional help as we go further with a CNA Please reach out if you have time and an interest.
TLS/HTTPS in core
- @leont said “I did start working on that”, but hasn’t shared a document yet
- New PSC will likely support HTTPS in core - there will be a meeting between old and new and it will likely continue
German Sovereign Tech fund is open for applications
- @sjn suggests a poll of who can commit time to the work that could be started based on an application
- Peter will help post US Perl conference
- We need someone who can do project management.
Secure by Default
- @stigtsp and @garu are putting together a list
- Sigstore and TUF could/should be on the list
Eclipse ORC WG
- @sjn - goal is to give feed back on the EU standards and regulations
- Project has a technical lead
- TPRF is a foundation, and Perl NOC hosts code. In theory neither can join the organization - an org needs to both host and be a foundation/non-profit.
CycloneDX 1.7 Sustainability fields
- @sjn - talked to someone who is working in the sustainability of open source projects
CPAN Meta Requirements and PURLs
- @sjn - no update
POSIX::2008 vulnerabilities
- @stigtsp mentioned needing to look at registering CVE for that.
SBOM/Supply Chain
- @sjn - has been sharing and still a WIP. The contents are in a good place at this time.
- Please read and provide feedback if you can
- Discussed at the OpenSSF numerous times
Upcoming Events
The Perl and Raku Conference in Las Vegas, NV - June 24-28, 2024- Open Source Summit Europe in Vienna, Austria - September 16-18 + 19-20 - Lots of people from OpenSSF + SBOM + Supply chain security communities
- London Perl Workshop - Saturday 26th October 2024 - possible talk opportunities
Other topics
- @Tux and @Tim worked on Crypt::OpenSSL::PKCS12
- @stigtsp how should a secure random module get moved to core? @garu explained the process for getting things moved into core - requests for comment, etc.
Next meeting
- July 18, 2024 at 17:00 UTC https://www.timeanddate.com/worldclock/converter.html?iso=20240718T170000&p1=1440&p2=1129&p3=136&p4=195&p5=16&p6=187&p7=233&p8=37&p9=250&p10=234&p11=256&p12=248