16:30 <ratliff> #startmeeting 16:30 <meetingology> Meeting started Mon Apr 2 16:30:59 2018 UTC. The chair is ratliff. Information about MeetBot at http://wiki.ubuntu.com/meetingology. 16:30 <meetingology> 16:30 <meetingology> Available commands: action commands idea info link nick 16:31 <ratliff> The meeting agenda can be found at: 16:31 <ratliff> [LINK] https://wiki.ubuntu.com/SecurityTeam/Meeting 16:31 <ratliff> [TOPIC] Announcements 16:31 <ratliff> Thanks to Simon Quigley (tsimonq2) for providing debdiffs for xenial-artful for atril (LP: #1759069) and 16:31 <ratliff> debdiffs for trusty-xenial for kdepim (LP: #1698180)! 16:31 <ubottu> Launchpad bug 1759069 in atril (Ubuntu Artful) "[CVE] Arbitrary command injection via DVI filename injection when printing to PDF" [Medium,Fix released] https://launchpad.net/bugs/1759069 16:31 <ubottu> Launchpad bug 1698180 in kdepim (Ubuntu Xenial) "[CVE] Send Later with Delay bypasses OpenPGP" [High,Fix released] https://launchpad.net/bugs/1698180 16:32 <ratliff> Thanks to Ray Link (rlink) for providint the debdiff for xenial for xmltooling (LP: #1752306)! 16:32 <ubottu> Launchpad bug 1752306 in xmltooling (Ubuntu Artful) "Security bug in XMLTooling-C before 1.6.4 [CVE-2018-0489]" [Undecided,Incomplete] https://launchpad.net/bugs/1752306 16:32 <ratliff> or providing it, rather 16:32 <ratliff> Your work is very much appreciated and will keep Ubuntu users secure. 16:32 <ratliff> [TOPIC] Weekly stand-up report 16:33 <ratliff> jdstrand: you're up (if you are around) 16:33 <jdstrand> I'm here :) 16:33 <jdstrand> This week I plan to work on: 16:33 <jdstrand> - address conntrack deprecation issues in ufw for 18.04 16:33 <jdstrand> - apparmor upload to 18.04 to fix webbrowser-app and mediascanner2 upgrades 16:33 <jdstrand> - finish up miscellaneous updates branches for snapd 16:33 <jdstrand> - pick up the snap/usn notification work as have time 16:33 <jdstrand> that's it from me 16:34 <ratliff> thanks, jdstrand! m_deslaur is on national holiday today 16:34 <ratliff> sbeattie: you are up! 16:34 <sbeattie> I'm in the happy place this week 16:34 <sbeattie> I'm publishing openjdk packages this morning 16:34 <sbeattie> There should be kernel USNs to publish later this week, I believe. 16:35 <sbeattie> I'm still slowly making progress on my gcc retpoline backport for precise 16:35 <sbeattie> Between that and catching up on a weeks worth of email, that'll probably consume my week. 16:35 <sbeattie> that's it from me 16:36 <sbeattie> sarnold: I think you're up? 16:37 <sarnold> I'm on community this week; I'll start the MIRs with pysmi today, and keep on moving down the line 16:37 <sarnold> I'm leaning towards accepting openjpeg2; it's still got a long way to go :( but it's come so far and is probably a better jpeg2000 library than what we're already using 16:37 <sarnold> .. any comments about that would be welcome :) 16:37 <sarnold> that's it for me, uh .. leosilva? 16:38 <leosilva> I'm on bug triage 16:38 <leosilva> I'm hunting this week and researching cves. 16:38 <ratliff> tons of ruby CVEs about to land, leosilva 16:38 <leosilva> ratliff: I believe it's back to yo 16:38 <leosilva> \o/ 16:38 <ratliff> I'm in the happy place this week. 16:39 <ratliff> My goal is to get the old kpi scripts checked into UCT along with some new kpi scripts and get all of the new kpis converted over to influx 16:40 <ratliff> Also a ton of internal work. 16:40 <ratliff> That's it for me. 16:40 <ratliff> [TOPIC] Highlighted packages 16:40 <ratliff> The Ubuntu Security team suggests that contributors look into merging Debian security updates in community-supported packages. If you would like to help Ubuntu but are not sure where to start, this is a great way to do so. See http://people.canonical.com/~ubuntu-security/d2u/ for available merges and https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures for details on preparing Ubuntu security updates. If you have any questions, feel 16:40 <ratliff> free to ask in #ubuntu-hardened. To find out other ways of helping out, please see https://wiki.ubuntu.com/SecurityTeam/GettingInvolved. 16:41 <ratliff> [TOPIC] Miscellaneous and Questions 16:41 <ratliff> Does anyone have any other questions or items to discuss? 16:42 <ratliff> Quick meeting this week! 16:43 <ratliff> We are seeing scattered reports of problems with the intel-microcode package. If you are experiencing any difficulties, please add your comments to LP #1760264 16:43 <ubottu> Launchpad bug 1759920 in linux (Ubuntu Artful) "duplicate for #1760264 intel-microcode 3.20180312.0 causes lockup at login screen(w/ linux-image-4.13.0-37-generic)" [High,Confirmed] https://launchpad.net/bugs/1759920 16:45 <ratliff> jdstrand, sbeattie, sarnold, leosilva: Thanks! 16:45 <ratliff> #endmeeting