Re: [opnfv-tech-discuss] [opnfv-tsc] Opening nominations for the Committers-at-Large TSC elections

2016-08-12 Thread Luke Hinds
> > > > > > > > > > > > > ___ > > > opnfv-tsc mailing list > > > opnfv-...@lists.opnfv.org <mailto:opnfv-...@lists.opnfv.org> > >

[opnfv-tech-discuss] Security Audit Discussions

2016-08-17 Thread Luke Hinds
Hi, As discussed on today's call, and etherpad to start to flesh out what a security audit would consist of for each release. This then gets discussed next week on the TSC. https://etherpad.opnfv.org/p/sec-audit Regards, Luke -- Luke Hinds | NFV Partner Engineering | Office of Techn

[opnfv-tech-discuss] simple list of project names

2016-08-20 Thread Luke Hinds
Hello, I need to gather a simple list (in an easily parsed format) of projects that have repos. I could crawl pages with urllib.request, but figured there might be something around already? Cheers, Luke -- Luke Hinds | NFV Partner Engineering | Office of Technology | Red Hat e: lhi

Re: [opnfv-tech-discuss] simple list of project names

2016-08-22 Thread Luke Hinds
there are a few of administraive repos like All-Projects, All-Users, > and Compliance that probably aren't interesting for you here) > > thanks, > -chris > > * Luke Hinds (lhi...@redhat.com) wrote: > > Hello, > > > > I need to gather a simple list (in an easily pars

[opnfv-tech-discuss] (no subject)

2016-08-24 Thread Luke Hinds
Hello, I wanted to open up to the community in more detail, the plans we have for the security audit. Its a four pronged process.. 1. Look at dependencies (modules / libraries) used and attempt to verify no known risks are associated with said dependencies. 2. Perform a secure code audit to loo

Re: [opnfv-tech-discuss] Stop commit count!

2016-08-30 Thread Luke Hinds
Hi Carlos, Are we sure its not a process the PTL may prefer? I find some folk don't like commits that cover more then one change, and instead prefer a single jira / commit to be used, even piecemeal for small changes. To digress though, Open Source projects do have a lot of cases of people bendin

[opnfv-tech-discuss] OPNFV Projects - Security Threat Analysis

2016-09-07 Thread Luke Hinds
Hello All, We will shortly be sharing the results of the threat analysis audit that is underway within the security group. This will be in the format of a email sent to the PTL of each audited project, with a restricted Google Drive link to the report. The PTL’s email, will be added with view /

Re: [opnfv-tech-discuss] [opnfv-tsc] Nomations for the 2016 OPNFV Committer Board Election

2016-09-13 Thread Luke Hinds
7;t used for the > recent TSC election. > > The nomination period will close at 5pm Pacific Time on September 23rd > (Friday). > > Thanks, > > Ray > > ___ > opnfv-tsc mailing list > opnfv-...@lists.opnfv.org > https

[opnfv-tech-discuss] OPNFV Security Article in linux.com

2016-09-13 Thread Luke Hinds
Nice write up on linux.com https://www.linux.com/blog/how-opnfv-earned-its-security-stripes-and-received-cii-best-practices-badge ___ opnfv-tech-discuss mailing list opnfv-tech-discuss@lists.opnfv.org https://lists.opnfv.org/mailman/listinfo/opnfv-tech-d

[opnfv-tech-discuss] [Security Advisory] Private key `vtep-privkey.pem` resides in ansible files directory for open-contrail role in Compass4NFV.

2016-09-21 Thread Luke Hinds
mmand: # find / -name vtep-privkey.pem | xargs rm Colorado No action is required for Colorado release users, as the fix has been applied directly into the master branch pre-release. ### Contact and References ### Reported by: Luke Hinds, Red Hat Contact: opnfv-secur...@lists.opnfv.org

[opnfv-tech-discuss] Results of Security Threat Analysis for Colorado.

2016-09-21 Thread Luke Hinds
/labs.detectify.com/2015/10/02/how-patreon-got-hacked-publicly-exposed-werkzeug-debugger/ [5] Regards, Luke - Security Group PTL -- Luke Hinds | NFV Partner Engineering | Office of Technology | Red Hat e: lhi...@redhat.com | irc: lhinds @freenode | m: +44 77 45 63 98 84 | t: +44 12 52 36 2483 0x3C2

Re: [opnfv-tech-discuss] OPNFV Packaging CI

2016-09-25 Thread Luke Hinds
ss mailing list > opnfv-tech-discuss@lists.opnfv.org > https://lists.opnfv.org/mailman/listinfo/opnfv-tech-discuss > -- Luke Hinds | NFV Partner Engineering | Office of Technology | Red Hat e: lhi...@redhat.com | irc: lhinds @freenode | m: +44 77 45 63 98 84 | t: +44 12 52 36 2483 _

[opnfv-tech-discuss] OPNFV on Github

2016-09-25 Thread Luke Hinds
have an org in place https://github.com/opnfv Regards, Luke -- Luke Hinds | NFV Partner Engineering | Office of Technology | Red Hat e: lhi...@redhat.com | irc: lhinds @freenode | m: +44 77 45 63 98 84 | t: +44 12 52 36 2483 ___ opnfv-tech-discuss ma

Re: [opnfv-tech-discuss] [openstack-dev] OPNFV on Github

2016-09-26 Thread Luke Hinds
agreement in OpenStack (https://ask.openstack.org/en/ >> question/89871/does-the-company-need-to-be-a-member- >> of-the-foundation-in-order-for-employees-to-contribute- >> code-on-behalf-of-the-company/) >> >> Thanks, >> >> Ray >> >> On Sun, Sep

Re: [opnfv-tech-discuss] OPNFV Packaging CI

2016-09-27 Thread Luke Hinds
On Tue, Sep 27, 2016 at 1:55 AM, Leif Madsen wrote: > On Sun, Sep 25, 2016 at 01:19:21PM +, Alexandru Avadanii wrote: > > Hi, Luke, > > My experience so far included mostly DEB packages, which fell in 3 > categories for Armband: > > > > - Backported from newer distro (lots of Ubuntu

Re: [opnfv-tech-discuss] OPNFV on Github

2016-10-05 Thread Luke Hinds
> > opnfv-tech-discuss mailing list > > opnfv-tech-discuss@lists.opnfv.org > > https://lists.opnfv.org/mailman/listinfo/opnfv-tech-discuss > > > > > > > > > > ___ > > opnfv-tech-discuss mailing list &

Re: [opnfv-tech-discuss] Jose Lausuch is the New Functest PTL

2016-10-12 Thread Luke Hinds
ed, changed or falsified. > Thank you. > > ___ > opnfv-tech-discuss mailing list > opnfv-tech-discuss@lists.opnfv.org > https://lists.opnfv.org/mailman/listinfo/opnfv-tech-discuss > -- Luke Hinds | NFV Partner Engineerin

Re: [opnfv-tech-discuss] Jose Lausuch is the New Functest PTL

2016-10-12 Thread Luke Hinds
Oh and second on such a great job and stewardship from Morgan On Wed, Oct 12, 2016 at 7:07 PM, Luke Hinds wrote: > Perfect man for the job. Congrats Jose. > > > On Tue, Oct 11, 2016 at 1:00 PM, wrote: > >> Hi TSC, >> >> I would like to inform that the Func

[opnfv-tech-discuss] Security Impact Review Reminder

2016-10-14 Thread Luke Hinds
can then review, or provide advice and feedback. Likewise, you can also include opnfv-secur...@lists.opnfv.org or place a [security] tag in your subject header on email discussions, if you want us to join in on a discussion. Many Thanks, Luke - Security Group PTL -- Luke Hinds | NFV Partner Engin

Re: [opnfv-tech-discuss] OPNFV on Github

2016-10-21 Thread Luke Hinds
t; inbound changes from GitHub a thing. >> > >> > -- >> > Leif Madsen | Partner Engineer - NFV & CI >> > NFV Partner Engineering >> > Red Hat >> > GPG: (D670F846) BEE0 336E 5406 42BA 6194 6831 B38A 291E D670 F846 >> > >> > _

[opnfv-tech-discuss] Security Vulnerability Classification in OPNFV JIRA

2016-11-01 Thread Luke Hinds
Hi, We now have a JIRA private security scheme that can be requested for assignment to projects. This will allow OPNFV projects to tag security issues raised in JIRA as private. I really would advise projects to make use of this JIRA feature. Being able to work on security fixes under a private

Re: [opnfv-tech-discuss] Graduation reviews discussion

2016-11-03 Thread Luke Hinds
g >> https://lists.opnfv.org/mailman/listinfo/opnfv-tech-discuss >> > > ___ > opnfv-tech-discuss mailing list > opnfv-tech-discuss@lists.opnfv.org > https://lists.opnfv.org/mailman/listinfo/opnfv-tech-discuss > > -- Luke Hinds | NF

Re: [opnfv-tech-discuss] OPNFV on Github

2016-11-04 Thread Luke Hinds
r Github account to include the address used to submit > changes to Gerrit. > > If you see any repos missing, or have any concerns, please let us know > at helpd...@opnfv.org. > > Regards, > Trevor Bramwell > Fantastic, thanks Trevor. > On Fri, Oct 21, 2016 at 10:38:03AM +

Re: [opnfv-tech-discuss] Q3'16 Quarterly Award winners

2016-11-28 Thread Luke Hinds
Thanks everybody, and really appreciate the award! -- Luke Hinds | NFV Partner Engineering | Office of Technology | Red Hat e: lhi...@redhat.com | irc: lhinds @freenode | m: +44 77 45 63 98 84 | t: +44 12 52 36 2483 On Mon, Nov 28, 2016 at 6:52 AM, Raymond Paik wrote: > All, > >

[opnfv-tech-discuss] Gotomeeting reservation

2016-12-13 Thread Luke Hinds
Hi, I'll be honest, I am completely out of sync with what we are doing for gotomeeting slots now. In the security group, we went to IRC only a while ago to free up a session slot, but we now need a gotomeeting session to walk over some stuff that will need audio / video for one time. The securit

[opnfv-tech-discuss] Security checks at Gate

2016-12-19 Thread Luke Hinds
Hi, Myself and Ash with help from Fatih are currently prototyping some new gates we plan to phase in overtime. The idea is that each commit made to an OPNFV repo will perform some checks. 1. Search for any strings containing passwords, ssh / tls certs and other stuff we don't want sitting around

Re: [opnfv-tech-discuss] [Opnfv-security] Security checks at Gate

2016-12-19 Thread Luke Hinds
aily/weekly job. > > Could you help to clarify it? > > On Mon, Dec 19, 2016 at 7:39 PM Luke Hinds wrote: > >> Hi, >> >> Myself and Ash with help from Fatih are currently prototyping some new >> gates we plan to phase in overtime. >> >> The idea is

Re: [opnfv-tech-discuss] [Opnfv-security] Security checks at Gate

2016-12-19 Thread Luke Hinds
Yujun, I said gate, but I meant check (so every time a commit happens, not a workflow +1) Luke On Mon, Dec 19, 2016 at 1:28 PM, Luke Hinds wrote: > Hi Yujun, > > I would need Fatih to comment as I am not that up to speed on CI. The > following is an albeit incomplete example of

Re: [opnfv-tech-discuss] [Opnfv-security] Security checks at Gate

2016-12-19 Thread Luke Hinds
es from an external repository, you again have a risk that > there are random changes to what is installed. This is fortunately mostly > relevant for installers. > Understood, there is not much I believe we can do here in respect of this work item. > -Tapio > > > > &g

Re: [opnfv-tech-discuss] [Opnfv-security] Security checks at Gate

2016-12-19 Thread Luke Hinds
> install > >> Linux packages from an external repository, you again have a risk that > there > >> are random changes to what is installed. This is fortunately mostly > relevant > >> for installers. > > > > > > Understood, there is not much

Re: [opnfv-tech-discuss] [Opnfv-security] Security checks at Gate

2016-12-19 Thread Luke Hinds
On Mon, Dec 19, 2016 at 5:07 PM, Tapio Tallgren wrote: > On 12/19/2016 04:49 PM, Luke Hinds wrote: > > > > On Mon, Dec 19, 2016 at 2:30 PM, Tapio Tallgren > wrote: > >> Luke, >> >> Since you are checking for binary files (point 2), will you also chec

[opnfv-tech-discuss] Meeting time change for Security Group

2016-12-21 Thread Luke Hinds
Hi, It was decided that the Security Group will change meeting times from 14:00 UTC to 16:00 utc to make it a little easier for folks attending from the US. Also with the Holiday season upon us, we will now not meet until the 04/01/2017 Thanks, Luke -- Luke Hinds | NFV Partner Engineering

[opnfv-tech-discuss] Project Termination for Inspector

2017-01-16 Thread Luke Hinds
would therefore like to propose termination 2 weeks from now by the TSC (31/01/17) No other projects / platform build processes have dependency on Inspector. Regards, Luke Hinds ___ opnfv-tech-discuss mailing list opnfv-tech-discuss@lists.opnfv.org https

Re: [opnfv-tech-discuss] [dovetail]Dovetail encryption for report

2017-01-17 Thread Luke Hinds
* >>> *** >>> *Lincoln Lavoie* >>> Senior Engineer, Broadband Technologies >>> >>> <https://www.iol.unh.edu/> >>> www.iol.unh.edu >>> 21 Madbury Rd., Ste. 100, Durham, NH 03824 >>> Mobile: +1-603-674-2755 <(603)%20674-2755> >>> lylav...@iol.unh.edu >&g

[opnfv-tech-discuss] Minutes from Security Group

2017-01-19 Thread Luke Hinds
Log: http://ircbot.wl.linuxfoundation.org/meetings/opnfv-sec/2017/opnfv-sec.2017-01-18-16.03.html Action items 1. ashyoung to finish gerrit hooks, and check code into repo. 2. lhinds fix anteater ignore issue 3. get release reproducibility as a topic on TSC Next meeting: Wednesday 26

Re: [opnfv-tech-discuss] Add license information for files without them

2017-02-18 Thread Luke Hinds
>> opnfv-tech-discuss mailing list >> opnfv-tech-discuss@lists.opnfv.org >> https://lists.opnfv.org/mailman/listinfo/opnfv-tech-discuss >> > -- > Yujun Zhang > > ___ > opnfv-tech-discuss mailing lis

[opnfv-tech-discuss] [functest] Security Scanning

2017-04-03 Thread Luke Hinds
Hi Functest'ers, I am aware I have not been as active on security scanning as I originally hoped, largely due to being v-busy working on upstream. I have also not seen much uptake in contributions from others or any requests for support or enhancements to make from operators / users of OPNFV. Wit

[opnfv-tech-discuss] Security Group moving to the Infra-WG

2017-04-03 Thread Luke Hinds
After discussions and voting in the OPNFV Security Group (SG) and the Infra-WG, it has been decided that the SG will move into the Infra-WG. This decision was largely based on the SG and Infra-WG having already worked well together on projects such as the core infrastructure security program, secu

Re: [opnfv-tech-discuss] [functest] Security Scanning

2017-04-04 Thread Luke Hinds
ates? If you don’t have much time > maybe we could propose it as an intern project. > > > > Regards, > > Jose > > > > > > > > *From:* opnfv-tech-discuss-boun...@lists.opnfv.org [mailto: > opnfv-tech-discuss-boun...@lists.opnfv.org] *On Behalf Of *Luke Hin

Re: [opnfv-tech-discuss] [functest] Security Scanning

2017-04-04 Thread Luke Hinds
gt; Jose > > > > > > > > *From:* opnfv-tech-discuss-boun...@lists.opnfv.org [ > mailto:opnfv-tech-discuss-boun...@lists.opnfv.org > ] *On Behalf Of *Luke Hinds > *Sent:* Monday, April 03, 2017 09:36 AM > *To:* opnfv-tech-discuss@lists.opnfv.org > *Subject:* [

[opnfv-tech-discuss] [infra] PTO next week

2017-04-05 Thread Luke Hinds
Hi Folks, I am on PTO next week, so won't be at the Infra-WG meeting on Monday. Cheers, Luke ___ opnfv-tech-discuss mailing list opnfv-tech-discuss@lists.opnfv.org https://lists.opnfv.org/mailman/listinfo/opnfv-tech-discuss

Re: [opnfv-tech-discuss] Add license information for files without them

2017-04-19 Thread Luke Hinds
> >> +2 for gate check instead of reminding by Email. >> >> It seems Ray has used another tool for license scanning. >> Luke Hinds 于2017年2月19日 周日06:32写道: >> >>> If its useful we could add something to our gate to check for license >>> text? We are t

[opnfv-tech-discuss] [infra] License checks in CI

2017-04-20 Thread Luke Hinds
b.com/Justin-chi/Lab/blob/master/add_license.sh -- Luke Hinds | NFV Partner Engineering | Office of Technology | Red Hat e: lhi...@redhat.com | irc: lhinds @freenode | m: +44 77 45 63 98 84 | t: +44 12 52 36 2483 ___ opnfv-tech-discuss mailing list opnfv

Re: [opnfv-tech-discuss] [infra] License checks in CI

2017-04-21 Thread Luke Hinds
Commons 4.0)? > > Plan to cover all languages (c/c++,java,python and shell scripts) and RST (CC 4.0) and Unix style patches. > Cheers, > > Ray > > On Thu, Apr 20, 2017 at 6:41 PM, Ash Young wrote: > >> Cool! I'm gonna check it out. Have a new version of PMD to also f

Re: [opnfv-tech-discuss] [infra] License checks in CI

2017-04-21 Thread Luke Hinds
know text to check for. [1] https://wiki.opnfv.org/display/DEV/Contribution+Guidelines Thanks, > > Bryan Sullivan | AT&T > > > > *From:* Luke Hinds [mailto:lhi...@redhat.com] > *Sent:* Thursday, April 20, 2017 7:44 AM > *To:* SULLIVAN, BRYAN L ; Raymond Paik <

[opnfv-tech-discuss] [infra] [security] Wiki page for Anteater

2017-05-17 Thread Luke Hinds
[1] https://wiki.opnfv.org/pages/viewpage.action?pageId=10294496 -- Luke Hinds | NFV Partner Engineering | Office of Technology | Red Hat e: lhi...@redhat.com | irc: lhinds @freenode | m: +44 77 45 63 98 84 | t: +44 12 52 36 2483 ___ opnfv-tech-discu

Re: [opnfv-tech-discuss] [infra] [security] Wiki page for Anteater

2017-05-18 Thread Luke Hinds
oprietary > toolchains (e.g. Blackduck – we should see if we can get an Open Source > project use license from them). > > > > Thanks, > > Bryan Sullivan | AT&T > > > > *From:* opnfv-tech-discuss-boun...@lists.opnfv.org [mailto: > opnfv-tech-discuss-boun...@lists.op

[opnfv-tech-discuss] [infra] Anteater code reviews

2017-05-25 Thread Luke Hinds
Hi All, If any of you could help review the following code, please do so: https://gerrit.opnfv.org/gerrit/#/c/34901/ Regards, Luke ___ opnfv-tech-discuss mailing list opnfv-tech-discuss@lists.opnfv.org https://lists.opnfv.org/mailman/listinfo/opnfv-te

Re: [opnfv-tech-discuss] [infra] [security] Wiki page for Anteater

2017-06-01 Thread Luke Hinds
luctant to approve a tool that mixes the dual intent of > license checks and trust, using an ultimately superficial method. I would > not want the community to give any impression that we had done a good and > thorough job on this, without actually doing it. > > > I am not strongly o

Re: [opnfv-tech-discuss] [releng][docs] Anteater checks

2017-06-19 Thread Luke Hinds
Avellana 213 > > Urb Portugal > > yrobl...@redhat.com M: +34605641639 > <http://redhatemailsignature-marketing.itos.redhat.com/> > <https://red.ht/sig> > -- Luke Hinds | NFV Partner Engineering | Office of Technology | Red Hat e: lhi...@redhat.com | irc: lhinds @freenode |

[opnfv-tech-discuss] Anteater Presentation

2017-06-21 Thread Luke Hinds
-- Luke Hinds | NFV Partner Engineering | Office of Technology | Red Hat e: lhi...@redhat.com | irc: lhinds @freenode | m: +44 77 45 63 98 84 | t: +44 12 52 36 2483 ___ opnfv-tech-discuss mailing list opnfv-tech-discuss@lists.opnfv.org https://lists.opnfv.org

[opnfv-tech-discuss] [infra][releng] verify-status plugin for gerrit

2017-06-25 Thread Luke Hinds
://gerrit.googlesource.com/plugins/verify-status/+doc/master/src/main/resources/Documentation/about.md -- Luke Hinds | NFV Partner Engineering | Office of Technology | Red Hat e: lhi...@redhat.com | irc: lhinds @freenode | m: +44 77 45 63 98 84 | t: +44 12 52 36 2483

Re: [opnfv-tech-discuss] [infra][releng] verify-status plugin for gerrit

2017-06-26 Thread Luke Hinds
e user comments from ci-voting jobs. >> >> There is a screencapture on the following documentation link that shows >> the difference that it makes. >> >> https://gerrit.googlesource.com/plugins/verify-status/+ >> doc/master/src/main/resources/Documentation/about.md

[opnfv-tech-discuss] [infra] Docker changes in Anteater

2017-06-27 Thread Luke Hinds
build.opnfv.org/ci/job/releng-anteater-docker-build-push-master/14/console [3] https://jira.opnfv.org/browse/RELENG-260 [4] https://gerrit.opnfv.org/gerrit/#/c/36571 [5] https://build.opnfv.org/ci/job/opnfv-security-audit-verify-master/133/console -- Luke Hinds | NFV Partner Engineering | Offic

Re: [opnfv-tech-discuss] [infra] Docker changes in Anteater

2017-06-27 Thread Luke Hinds
ell > > [1] https://gerrit.opnfv.org/gerrit/#/c/36601/ > [2] https://build.opnfv.org/ci/job/releng-anteater-docker- > build-push-master/14/console > > On Tue, Jun 27, 2017 at 01:50:15PM +0100, Luke Hinds wrote: > > Hi, > > > > Patch [1] resulted in docker build failing

Re: [opnfv-tech-discuss] [infra] Docker changes in Anteater

2017-06-27 Thread Luke Hinds
r is running again. > > Regards, > Trevor Bramwell > > [1] https://gerrit.opnfv.org/gerrit/#/c/36601/ > [2] https://build.opnfv.org/ci/job/opnfv-security-audit- > verify-master/148/console > > On Tue, Jun 27, 2017 at 05:15:40PM +0100, Luke Hinds wrote: > > Hi Trevor,

[opnfv-tech-discuss] UK / London OPNFV meetup

2017-06-27 Thread Luke Hinds
Hi, I would like to see if there is any interest in having a UK (possibly London) OPNFV meetup. This would be an informal event, either in a pub somewhere or some office space if a kind donor appears. If it goes well, then we can build from there. I hope to see at least five + positives, to sign

Re: [opnfv-tech-discuss] [Infra][Pharos][Releng][Octopus] Proposal to implement installers' quickstart wrapper scripts

2017-06-29 Thread Luke Hinds
______ > opnfv-tech-discuss mailing list > opnfv-tech-discuss@lists.opnfv.org > https://lists.opnfv.org/mailman/listinfo/opnfv-tech-discuss > > -- Luke Hinds | NFV Partner Engineering | Office of Technology | Red Hat e: lhi...@redhat.c

[opnfv-tech-discuss] Roll out of CI Gate Security (please read if PTL)

2017-06-29 Thread Luke Hinds
for you. Each project, will have its own exception file (think of this as a filter that allows certain strings to pass unchallenged). For reference, you can see how functest are starting to work with their own file [1] [1] https://git.opnfv.org/releng-anteater/commit/exceptions/functest.yaml Luke

Re: [opnfv-tech-discuss] [Infra][Pharos][Releng][Octopus] Proposal to implement installers' quickstart wrapper scripts

2017-06-30 Thread Luke Hinds
of install.sh > # located at https://github.com/docker/docker-install > # before executing. > ``` > > Best Regards, > Qi Liang > -- > *From:* Luke Hinds [lhi...@redhat.com] > *Sent:* Thursday, June 29, 2017 18:32 > *To:* li

[opnfv-tech-discuss] OPNFV UK User Group

2017-07-03 Thread Luke Hinds
f you wish to secure a place (and intend to turn up). The agenda will be set over the next few weeks. https://www.meetup.com/OPNFV-UK-User-Group/events/241208551/ -- Luke Hinds | NFV Partner Engineering | Office of Technology | Red Hat e: lhi...@redhat.com | irc: lhinds @freenode | m: +44 77 45

Re: [opnfv-tech-discuss] [Infra][Pharos][Releng][Octopus] Proposal to implement installers' quickstart wrapper scripts

2017-07-03 Thread Luke Hinds
t; Is it ok? > > Yep, I am totally ok with that approach. That way we give people who want the secure option, a means to do so. Thanks for being receptive to this.Good work! > Best Regards, > Qi Liang > -- > *From:* Luke Hinds [lhi...@redhat.com]

Re: [opnfv-tech-discuss] [anteater] build log for anteator

2017-07-13 Thread Luke Hinds
__ > opnfv-tech-discuss mailing list > opnfv-tech-discuss@lists.opnfv.org > https://lists.opnfv.org/mailman/listinfo/opnfv-tech-discuss > > -- Luke Hinds | NFV Partner Engineering | Office of Technology | Red Hat e: lhi...@redhat.com |

[opnfv-tech-discuss] Secure use of curl / wget and external artefacts

2017-07-14 Thread Luke Hinds
Anteater has raised that a lot of projects are using curl / wget to pull down artefacts from external sites that are often instantiated (in the case of an IMG file) or piped through bash (in the case of a shell script). This is dangerous and has known risks, so I have put together a wiki page expl

Re: [opnfv-tech-discuss] [anteater] build log for anteator

2017-07-14 Thread Luke Hinds
ns task. >> >> Luke, I will deal with this. >> >> Thanks Julien. > >> Luke Hinds 于2017年7月13日周四 下午10:13写道: >> >>> How do you mean by build log Yujun? I am always interested in feedback / >>> improvements. >>> >>> >>>

[opnfv-tech-discuss] Lab as a Service - Installer Support

2017-07-17 Thread Luke Hinds
have interfaces that can accept the requests and process deployment status. Any question, please ask over this email or attend the infra-wg group. Many Thanks, Luke -- Luke Hinds | NFV Partner Engineering | Office of Technology | Red Hat e: lhi...@redhat.com | irc: lhinds @freenode | m: +44 77

Re: [opnfv-tech-discuss] [OPNFV Helpdesk #43579] [linuxfoundation.org #43579] RE: uploading UI code to OPNFV

2017-07-27 Thread Luke Hinds
> > ___ > > opnfv-tech-discuss mailing list > > opnfv-tech-discuss@lists.opnfv.org > > https://lists.opnfv.org/mailman/listinfo/opnfv-tech-discuss > > > ___

Re: [opnfv-tech-discuss] Lab as a Service - Installer Support

2017-07-31 Thread Luke Hinds
Second retry of this email to gauge interest of other installs. So far we have Compass4NFV. On Mon, Jul 17, 2017 at 3:39 PM, Luke Hinds wrote: > Dear Installer Projects, > > I have an action from the infra-wg to gauge which installers can support > LaaS. > > Please peruse

[opnfv-tech-discuss] [releng] Anteater gerrit comment formatting

2017-08-31 Thread Luke Hinds
Hi, I raised the following JIRA [1], but not sure of the best way to fix the jjb script (don't understand the logic with the sed command) Would someone be able to take this on, as its leaving quite some messy comments on quite a few anteater jobs. [1] https://jira.opnfv.org/browse/RELENG-308 Ch

Re: [opnfv-tech-discuss] [releng] Committer list per Releng repository

2017-12-10 Thread Luke Hinds
; > > > > > > > I plan to bring this topic to TSC on December 12th if the vote passes. > > > > > > > > [1] https://gerrit.opnfv.org/gerrit/#/admin/projects/?filter=releng > > > > > > > > /Fatih > > > > > -- >

[opnfv-tech-discuss] [infra] Infra-WG Meeting cancelled

2018-01-08 Thread Luke Hinds
Hello, We have had to cancel today's infra working group meeting, due to an personal event on my side meaning I cannot attend to chair. As Jack and Faith are also out / busy, a decision was made to cancel for now. Regards, Luke ___ opnfv-tech-discuss m

[opnfv-tech-discuss] [infra] Meeting time and calender invites.

2018-01-15 Thread Luke Hinds
lines messaged back. My proposal, manage your own calender and then if your timezone changes, you can just move the invite yourself. Cheers, Luke -- Luke Hinds | NFV Partner Engineering | CTO Office | Red Hat e: lhi...@redhat.com | irc: lhinds @freenode | m: +44 77 45 63 98 84 | t: +44 12 52 36

Re: [opnfv-tech-discuss] Anteater status and link issue

2018-02-12 Thread Luke Hinds
. Once the above is in place, docs will be clearer to follow, project will be more presentable, with more coverage in finding vulns will be wider. > > > Thanks, > > Bryan Sullivan | AT&T > > > > _______ > opnfv-tech-discus

Re: [opnfv-tech-discuss] Anteater status and link issue

2018-02-13 Thread Luke Hinds
On Tue, Feb 13, 2018 at 12:17 AM, SULLIVAN, BRYAN L (BRYAN L) < bryan.sulli...@research.att.com> wrote: > Comments etc inline > > > > Thanks, > > Bryan Sullivan | AT&T > > > > *From:* Luke Hinds [mailto:lhi...@redhat.com] > *Sent:* Monday, Febru

Re: [opnfv-tech-discuss] Anteater status and link issue

2018-02-13 Thread Luke Hinds
uld have the URL / Domain / IP stuff working later in the week. On Tue, Feb 13, 2018 at 9:41 AM, Luke Hinds wrote: > > > On Tue, Feb 13, 2018 at 12:17 AM, SULLIVAN, BRYAN L (BRYAN L) < > bryan.sulli...@research.att.com> wrote: > >> Comments etc inline >> >>

Re: [opnfv-tech-discuss] {releng-anteater] project_scan.py check for top-level license needs enhancements

2018-02-16 Thread Luke Hinds
Thanks, I'll take a look. On 16 Feb 2018 5:45 pm, "SULLIVAN, BRYAN L (BRYAN L)" < bryan.sulli...@research.att.com> wrote: > I’m not sure how/where to raise this as a bug, so I created a JIRA issue: > https://jira.opnfv.org/browse/RELENG-346 > > > > Anteater needs to verify that the project top-le

[opnfv-tech-discuss] [releng] Secrets in environment variables

2018-02-20 Thread Luke Hinds
ey in the environment, rather then a config file..is this workable? e.g... export VT_KEY='' echo $VT_KEY -- Luke Hinds | NFV Partner Engineering | CTO Office | Red Hat e: lhi...@redhat.com | irc: lhinds @freenode | t: +44 12 52 36 2483 ___ opn

Re: [opnfv-tech-discuss] [releng] Secrets in environment variables

2018-03-08 Thread Luke Hinds
t be echo/cat > > during the CI execution. > > It requires a Credentials Binding plugin. > > @Trevor, Aric, can you double check is it installed already? > > We use this method to avoid API token leak issue in internal CI. > > > > [1], https://docs.openstack.or

[opnfv-tech-discuss] [releng][security][infra] Anteater Improvements

2018-03-08 Thread Luke Hinds
Hello, I have some changes to improve the reporting ability and hopefully tone down the false positives. Aneater will now interface with the VirusTotal public API: 1. If anteater finds a public IP address, the DNS history will be quiered to see if the IP has past or present associations with mal

Re: [opnfv-tech-discuss] [releng][security][infra] Anteater Improvements

2018-03-08 Thread Luke Hinds
ci [mailto:fatih.degirme...@ericsson.com] > *Sent:* Thursday, March 08, 2018 7:01 AM > *To:* SULLIVAN, BRYAN L (BRYAN L) ; Luke > Hinds ; opnfv-tech-discuss opnfv.org> > > *Subject:* Re: [opnfv-tech-discuss] [releng][security][infra] Anteater > Improvements > > > > Hi

Re: [opnfv-tech-discuss] [releng][security][infra] Anteater Improvements

2018-03-09 Thread Luke Hinds
explicitly added to exception list for the > > corresponding project, do you mean that we will stop flagging > changes/files > > that contain wget/curl against unknown IPs if they are not marked as > > malicious on VirusTotal? > > > > We also had plans to make anteater checks voti

Re: [opnfv-tech-discuss] [releng][security][infra] Anteater Improvements

2018-03-09 Thread Luke Hinds
_audits: file_contents: - ^# - \.onap\.org\/files\/.*\/*\.iso|img|yaml|tar Hopefully its possible to see how flexible the tool is now. On Fri, Mar 9, 2018 at 9:24 AM, Luke Hinds wrote: > A simple way to solve this is using regex. You can really build up > multiple conditions, for example the fo

Re: [opnfv-tech-discuss] [releng][security][infra] Anteater Improvements

2018-03-09 Thread Luke Hinds
Sorry for spamming you folks, but the last one was broken: https://regexr.com/3lv46 On Fri, Mar 9, 2018 at 9:36 AM, Luke Hinds wrote: > Another example with domain based urls: > > https://regexr.com/3lv1o > > All we need do then is make an entry in anteater as follows &g

[opnfv-tech-discuss] [releng] Anteater maintenance

2019-01-07 Thread Luke Hinds
Hi RelEng Folks, I am not as involved in OPNFV any longer. I still get a few emails around anteater information at gate. Would someone else like to take over managing the issues at gate or should we decommission the project (in opnfv)? Also it's running an old version now, there is a later versi

Re: [opnfv-tech-discuss] [releng] Anteater maintenance

2019-01-09 Thread Luke Hinds
; for a while. > I agree, if OPNFV is not minding that store, they should consider turning > it down. > > Thanks, > Bryan Sullivan | AT&T > -- > *From:* opnfv-tech-discuss@lists.opnfv.org [ > opnfv-tech-discuss@lists.opnfv.org] on behalf of Luke

[opnfv-tech-discuss] Security PTL

2019-07-01 Thread Luke Hinds
Luke Hinds -- Luke Hinds | CTO Office | Red Hat e: lhi...@redhat.com | irc: lhinds @freenode | t: +44 12 52 36 2483 -=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#23306): https://lists.opnfv.org/g/opnfv-tech-discuss/message/23306 Mute This Topic:

Re: [opnfv-tech-discuss] Security PTL

2019-07-18 Thread Luke Hinds
of a better engineer to take up the role as PTL. Regards, Luke On Fri, Jun 28, 2019 at 10:03 AM Luke Hinds wrote: > Hello, > > I would like to notify the TSC that I wish to step down as Security PTL. > > I have not been active in the role for a long time now, so this very much

Re: [opnfv-tech-discuss] [OPNFV Helpdesk #43579] [linuxfoundation.org #43579] RE: uploading UI code to OPNFV

2017-07-27 Thread Luke Hinds via RT
> > ___ > > opnfv-tech-discuss mailing list > > opnfv-tech-discuss@lists.opnfv.org > > https://lists.opnfv.org/mailman/listinfo/opnfv-tech-discuss > > > ___