8000 Monthly Chat Agendas March (2021-03-01 and 2021-02-15) Meeting Agenda · Issue #2008 · coreruleset/coreruleset · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content
8000

Monthly Chat Agendas March (2021-03-01 and 2021-02-15) Meeting Agenda #2008

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
dune73 opened this issue Feb 10, 2021 · 1 comment
Closed

Comments

@dune73
Copy link
Member
dune73 commented Feb 10, 2021

This is the Agenda for the Monthly CRS Chats.

The general chat is going to happen on https://owasp.slack.com in the channel #coreruleset on Monday, March 1st, at 20:30 CET. That's the 1st Monday of the month. A separate issue chat is happening at the same location, same time on Monday, March 15th. That's the 3rd Monday of the month.

Items on the Agenda: (see previous meetings decisions: here)

What happend in the meantime since the chat last month

Outside development

  • Blogpost: How to test the WAF with CRS as example
  • Blogpost: Payload detection challenge testing CRS against other offerings
  • There is a new agenda template to kickstart a new meeting agenda for the monthly meetings Link
  • @dune73 will appear in the Infosec & OSInt show podcast on Friday, March 5, 2021 to talk about CRS and WAFs in general.

PRs that have been merged since the last meeting

Open PRs

Open PRs marked "work in progress" / needs action

Other items

  • What's up with the next release?
  • Are we generally open to enter an agreement with a sponsor to provide specific rule exclusions and to maintain them over time?
  • Proposed course forward for ftw:
    We are stuck on python 2 with ftw and it's no longer supported. Yet upgrading is tricky.
    • step 1: adopt ftw for py3 with minimal adjustments to tests. According to @fzipi there is no way around adopting 2 existing tests since the formatting of binary data as raw_request no longer works the same way. We need to use encoded_request. @fzipi thinks he can do a PR within 10 days.
    • step 2: run ftw and new go-ftw (written in Go by @fzipi) version in parallel. Tests would be transformed by a script to work with go-ftw
    • step-3: replace ftw with go-ftw and adopt all changes to new, a wee bit cleaner yaml test format with stricter variable typing. go-ftw is way faster than our ftw. There is still quite some work with tests and better interfaces to make this viable.
  • CRS plugin architecture - this is a fleshed out proposal with a plugin architecture and the new include statements that load it by default.

Open Issues - Separate Issues Meeting (Monday, March 15th)

Of the 8 issues discussed in February, 4 have been closed in the meantime. The other 4 are taken up here again (in the slots 1-4).

We generally cover 10 issues per month in a separate issue meeting. Add them as you see fit.

How to get to our slack and join the meeting?

If you are not yet on the OWASP Slack, here is your invite: https://owasp-slack.herokuapp.com/ .

Everybody is welcome to join our community chat.

@franbuehler
Copy link
Contributor
franbuehler commented Mar 1, 2021

Decisions

PRs

Other items

  • Next release:

Open Issues - Separate Issues Meeting (Monday, March 15th)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants
0