== Meeting information == * #ubuntu-meeting Meeting, 26 Mar at 16:31 — 16:46 UTC * Full logs at [[http://ubottu.com/meetingology/logs/ubuntu-meeting/2018/ubuntu-meeting.2018-03-26-16.31.log.html]] == Meeting summary == ''LINK:'' https://wiki.ubuntu.com/SecurityTeam/Meeting === Announcements === The discussion about "Announcements" started at 16:32. * ''LINK:'' https://boards.greenhouse.io/canonical/jobs/1084137#.WqvsZ6jwaUk === Weekly stand-up report === The discussion about "Weekly stand-up report" started at 16:33. === Highlighted packages === The discussion about "Highlighted packages" started at 16:43. === Miscellaneous and Questions === The discussion about "Miscellaneous and Questions" started at 16:43. == Vote results == == Done items == * (none) == People present (lines said) == * ratliff (24) * jdstrand (11) * mdeslaur (10) * sarnold (8) * chrisccoulson (6) * leosilva (4) * meetingology (3) * ubottu (2) * tsimonq2 (1) == Full Log == 16:31 #startmeeting 16:31 Meeting started Mon Mar 26 16:31:46 2018 UTC. The chair is ratliff. Information about MeetBot at http://wiki.ubuntu.com/meetingology. 16:31 16:31 Available commands: action commands idea info link nick 16:32 The meeting agenda can be found at: 16:32 [LINK] https://wiki.ubuntu.com/SecurityTeam/Meeting 16:32 [TOPIC] Announcements 16:32 Thanks to Simon Quigley (tsimonq2) for providing an update in xenial for atril (LP: #1735418) and updates in xenial and artful for plasma-workspace (LP: #1748247) 16:32 Launchpad bug 1735418 in atril (Ubuntu Bionic) "[CVE] Command injection with cbt files" [Medium,Fix released] https://launchpad.net/bugs/1735418 16:33 Launchpad bug 1748247 in plasma-workspace (Ubuntu Bionic) "[CVE] Arbitrary command execution in the removable device notifier" [High,Fix released] https://launchpad.net/bugs/1748247 16:33 Your work is very much appreciated and will keep Ubuntu users secure. 16:33 The Ubuntu Security Team is hiring! See the job posting at 16:33 [LINK] https://boards.greenhouse.io/canonical/jobs/1084137#.WqvsZ6jwaUk 16:33 [TOPIC] Weekly stand-up report 16:33 jdstrand: you're up 16:34 hi! 16:34 FYI, the portions of layouts and portals that are for me are now done (there might be some additional PRs here and there, but I think we can now mark the cards as DONE, which I'm in the process of doing). This week I plan to work on: 16:34 - there are a few emergency PRs for 18.04 related to systemd and glvnd breakage 16:34 - steam-support interface 16:34 - lxd partial confinement not working bug 16:34 - org.gnome.Shell.Screencast interface 16:34 - work done the backlog lane as have time 16:34 down* 16:35 I figure after this week I'm going to pivot to snaps and usns 16:35 that's it from me 16:35 * mdeslaur takes the mike 16:35 heh, yes. you're up :) 16:35 is this thing on? 16:35 I'm in the happy place this week 16:36 I just published some more tiff updates 16:36 and I think I've tracked down the regression in unixodbc 16:36 I need to test some wayland updates somehow 16:36 and I'll pick something else off the list 16:36 ratliff: hey thanks :) 16:36 that's about it, sbeattie? 16:36 sbeattie is on vacation this week 16:37 tsimonq2: nice to see you and we thank you! :) 16:37 ah! who's next 16:37 sarnold: you are up 16:37 hey tsimonq2 :) 16:37 I'm on bug triage this week 16:37 I'm working on the volume-key mir, moving down the list.. 16:38 hrm, I can't recall which one is next on the list 16:38 python-nacl 16:38 aha! thanks 16:38 and I saw john check in some apparmor patches, maybe review new patches if he's got them 16:39 and it's a short week, I'm off friday 16:39 that's it for me, chrisccoulson? 16:39 I've got a thunderbird update to do, and also yet another firefox update 16:40 I'll need to spend a small amount of time on 1 embargoed issue 16:40 And I've got 1 internal thing to work on 16:41 Hopefully I'll get back to working on this apparmor audit work after that 16:41 It's a short week for me (I'm off Friday as well) 16:41 That's me done 16:41 I'm on community this week. 16:42 I will mostly focus on internal tasks (including ideally talking to candidates for the Tech Lead job). 16:42 leosilva: on to you 16:42 I'm on cve-triage this week 16:42 I have a zsh to update - zsh that cool bash tool. 16:43 and I'll keep hunting pkgs to update 16:43 that is all, ratliff it's back to you 16:43 [TOPIC] Highlighted packages 16:43 The Ubuntu Security team suggests that contributors look into merging Debian security updates in community-supported packages. If you would like to help Ubuntu but are not sure where to start, this is a great way to do so. See http://people.canonical.com/~ubuntu-security/d2u/ for available merges and https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures for details on preparing Ubuntu security updates. If you have any questions, feel 16:43 free to ask in #ubuntu-hardened. To find out other ways of helping out, please see https://wiki.ubuntu.com/SecurityTeam/GettingInvolved. 16:43 [TOPIC] Miscellaneous and Questions 16:44 Does anyone have any other questions or items to discuss? 16:46 jdstrand, mdeslaur, sarnold, chrisccoulson, leosilva: Thanks! 16:46 thanks ratliff! 16:46 #endmeeting Generated by MeetBot 0.1.5 (http://wiki.ubuntu.com/meetingology)