Hi all,

I would like to bring up following security issue in this meeting if there is 
interest for it in the group:

- Collaboration within Yocto project when a critical vulnerability like 
Heartbleed/Shellshock occurs
We applied GNU patches in our branches, tested and sent updates to our 
customers, then Yocto came up with a patch and we took that one later (our own 
work did become redundant). It would have been better if we collaborated within 
the Yocto project and together created a security patch, tested it for 
different architectures and sent a Security Notification/Advisory to the list 
with background/summary of CVEs, tests ..etc? (i.e. divided the work between us 
).  

Do you think it is good idea to create a security team and discuss security 
topics in that list? Is there any volunteer/interest?  

Thanks
Sona 



From: yocto-boun...@yoctoproject.org [mailto:yocto-boun...@yoctoproject.org] On 
Behalf Of Jolley, Stephen K
Sent: den 7 oktober 2014 04:20
To: yocto@yoctoproject.org
Subject: [yocto] Agenda: Yocto Project Technical Team Meeting - Tuesday, 
October 7, 2014 8:00 AM US Pacific Time

Tuesday, October 7, 2014 8:00 AM US Pacific Time

Agenda:
 
* Opens collection - 5 min (Stephen)
* Yocto Project status - 5 min (Stephen/team)
https://wiki.yoctoproject.org/wiki/Yocto_Project_v1.7_Status
https://wiki.yoctoproject.org/wiki/Yocto_1.7_Schedule
https://wiki.yoctoproject.org/wiki/Yocto_1.7_Features
* SWAT team rotation: Beth -> Paul
https://wiki.yoctoproject.org/wiki/Yocto_Build_Failure_Swat_Team
* Opens - 10 min 
* Team Sharing - 10 min


We encourage people attending the meeting to logon the Yocto Project IRC 
chancel during the meeting (optional):

Yocto IRC: http://webchat.freenode.net/?channels=#yocto
IRC Tutorial: http://www.irchelp.org/irchelp/irctutorial.html 

Conference Details:
Company:           WIND RIVER SYS
Ready-Access Number: 8007302996/9139049836
Access Code:     2705751

For International numbers see: 
https://www.yoctoproject.org/tools-resources/community/weekly-technical-call

Thanks,

Stephen K. Jolley
Yocto Project Program Manager
INTEL, MS JF1-255, 2111 N.E. 25th Avenue, Hillsboro, OR 97124 
I   Work Telephone:          (503) 712-0534
(    Cell:                                (208) 244-4460
((Email:                             stephen.k.jol...@intel.com

-- 
_______________________________________________
yocto mailing list
yocto@yoctoproject.org
https://lists.yoctoproject.org/listinfo/yocto

Reply via email to