8000 Monthly Chat Agenda April 2022 (2022-04-04 and 2022-04-18) · Issue #2453 · coreruleset/coreruleset · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content
Monthly Chat Agenda April 2022 (2022-04-04 and 2022-04-18) #2453
Closed
@dune73

Description

@dune73

This is the Agenda for the Monthly CRS Chat.

The general chat is going to happen on https://owasp.slack.com in the channel #coreruleset on Monday, 2022-04-04, at 20:30 CET. That's the 1st Monday of the month. A separate issue chat is happening at the same location, same time on Monday, 2022-04-18. That's the 3rd Monday of the month. Please note that we have a CRS calendar (maintained by @fzipi).

Items on the Agenda: (see previous meetings decisions: here)

What happend in the meantime since the chat last month

Outside development

PRs that have been merged since the last meeting

10000

We merged 22 PRs since the last monthly project chat.

Open PRs

Open PRs marked DRAFT or work in progress or needs action

Open Non-Core PRs

Dev retreat topics

  • Demo / Sandbox site:

    • /juiceshop backend is active and running in production.
    • all requests that match a rule under /juiceshop receive a 403 Forbidden with the usual JSON/CSV/TXT output.
    • I’m writing an HTML matched rules output that should be the default output format for /juiceshop.
    • There’re some FPs on juiceshop and we should develop an exclusion rule set for it (for example allow PUT method).
    • Since there’re RCE and SQLi vulnerabilities, we need to find a clean solution to “factory reset” the backend (maybe a crontab job that kills the container and recreates it via docker-compose).
  • Documentation:

    • 📊 Anomaly scoring content: still stuck at 99% complete. Now has feedback from @dune73. Needs re-visiting.
    • 🔧 Development section: now in a PR! @theseion has left some comments, which need to be looked into.
      • Help required with the following headings:
        • When and Why to Anchor Regular Expressions
        • Lazy Matching
        • Writing RE2-compatible Regular Expressions
      • Testing section: ported from the wiki.
    • 🚒 Engine options and integrations: still todo.
    • 🧹 Final tidy up: todo, needs everything else to be finished first.
  • Technical Blog Posts: FIXME

  • Status page: There has not been additional progress in the Status page project.

  • Coraza: FIXME

Other items

  • 🔌 Plugins: Should they be allowed to set global (server context) ModSec/engine settings (e.g. SecCollectionTimeout)?
  • Plugin activation / disabling per VH?
  • Feature Freeze

Open Issues - Separate Issues Meeting (Monday, FIXME)

Status of issues covered last month

  • Issue slot 1: #FIXME
  • Issue slot 2: #FIXME
  • Issue slot 3: #FIXME
  • Issue slot 4: #FIXME
  • Issue slot 5: #FIXME
  • Issue slot 6: #FIXME
  • Issue slot 7: #FIXME
  • Issue slot 8: #FIXME
  • Issue slot 9: #FIXME
  • Issue slot 10: #FIXME

Stats

  • Covered in chat: FIXME
  • Closed: FIXME
  • Pending: FIXME

This month's issues

There are FIXME open issues at the beginning of the issue chat.

We generally cover 10 issues per month in a separate issue meeting. Add them as you see fit.

How to get to our slack and join the meeting?

If you are not yet on the OWASP Slack, here is your invite: https://owasp.org/slack/invite .

Everybody is welcome to join our community chat.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions

      0