Meeting Agenda for 2024-07-26

Here’s the Agenda for 2024-07-26T19:00:00Z's meeting (most topics repurposed from 2024-07-12 meeting due to low participation:

  • Additional agenda items
  • @dfh: Update emails project, next steps
  • Via @aidalgol Should Aux Security be capable of handling embargo updates? What are the concequences of that decision?
  • @dfh Short recap of thoughts around OpenSSH vuln
  • @dfh Update on secrets project
  • Any other business

Unfinished discussions points from past calls

Call will be at the same place as always
Here is the link for the agenda/minutes

1 Like

Should we add/ enforce commit signing for auxolotl/security e.g. #1 - Add meeting notes location - auxolotl/security - Auxolotl Forge?

I generally recommend commit signing, but one thing to remember when requiring it is that CI may need to commit as well which requires additional key management. Some processes may run into trouble with that.


What’s the “problem” or risk that you address by using signing?

The reason I’m asking that I personally believe we should not use security features for the sake of security, but for the sake of actually solving problems.
Wording the problem IMO also helps with the question if that’s the best solution :wink:

I’m re-purposing the agenda for the 26th of July since no-one showed.

@committee_security Please speak up if the new times don’t work for you.
I would love to make regular team meetings work as well as SIGDOCS…