8000 Monthly Chat Agenda April 2022 (2022-04-04 and 2022-04-18) · Issue #2453 · coreruleset/coreruleset · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

Monthly Chat Agenda April 2022 (2022-04-04 and 2022-04-18) #2453

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
dune73 opened this issue Mar 26, 2022 · 3 comments
Closed

Monthly Chat Agenda April 2022 (2022-04-04 and 2022-04-18) #2453

dune73 opened this issue Mar 26, 2022 · 3 comments

Comments

@dune73
Copy link
Member
dune73 commented Mar 26, 2022

This is the Agenda for the Monthly CRS Chat.

The general chat is going to happen on https://owasp.slack.com in the channel #coreruleset on Monday, 2022-04-04, at 20:30 CET. That's the 1st Monday of the month. A separate issue chat is happening at the same location, same time on Monday, 2022-04-18. That's the 3rd Monday of the month. Please note that we have a CRS calendar (maintained by @fzipi).

Items on the Agenda: (see previous meetings decisions: here)

What happend in the meantime since the chat last month

Outside development

PRs that have been merged since the last meeting

We merged 22 PRs since the last monthly project chat.

Open PRs

Open PRs marked DRAFT or work in progress or needs action

Open Non-Core PRs

Dev retreat topics

  • Demo / Sandbox site:

    • /juiceshop backend is active and running in production.
    • all requests that match a rule under /juiceshop receive a 403 Forbidden with the usual JSON/CSV/TXT output.
    • I’m writing an HTML matched rules output that should be the default output format for /juiceshop.
    • There’re some FPs on juiceshop and we should develop an exclusion rule set for it (for example allow PUT method).
    • Since there’re RCE and SQLi vulnerabilities, we need to find a clean solution to “factory reset” the backend (maybe a crontab job that kills the container and recreates it via docker-compose).
  • Documentation:

    • 📊 Anomaly scoring content: still stuck at 99% complete. Now has feedback from @dune73. Needs re-visiting.
    • 🔧 Development section: now in a PR! @theseion has left some comments, which need to be looked into.
      • Help required with the following headings:
        • When and Why to Anchor Regular Expressions
        • Lazy Matching
        • Writing RE2-compatible Regular Expressions
      • Testing section: ported from the wiki.
    • 🚒 Engine options and integrations: still todo.
    • 🧹 Final tidy up: todo, needs everything else to be finished first.
  • Technical Blog Posts: FIXME

  • Status page: There has not been additional progress in the Status page project.

  • Coraza: FIXME

Other items

  • 🔌 Plugins: Should they be allowed to set global (server context) ModSec/engine settings (e.g. SecCollectionTimeout)?
  • Plugin activation / disabling per VH?
  • Feature Freeze

Open Issues - Separate Issues Meeting (Monday, FIXME)

Status of issues covered last month

  • Issue slot 1: #FIXME
  • Issue slot 2: #FIXME
  • Issue slot 3: #FIXME
  • Issue slot 4: #FIXME
  • Issue slot 5: #FIXME
  • Issue slot 6: #FIXME
  • Issue slot 7: #FIXME
  • Issue slot 8: #FIXME
  • Issue slot 9: #FIXME
  • Issue slot 10: #FIXME

Stats

  • Covered in chat: FIXME
  • Closed: FIXME
  • Pending: FIXME

This month's issues

There are FIXME open issues at the beginning of the issue chat.

We generally cover 10 issues per month in a separate issue meeting. Add them as you see fit.

How to get to our slack and join the meeting?

If you are not yet on the OWASP Slack, here is your invite: https://owasp.org/slack/invite .

Everybody is welcome to join our community chat.

@franbuehler
Copy link
Contributor
franbuehler commented Apr 4, 2022

Decisions

PRs

RC1 Discussion and notes

Issues

@dune73 dune73 added this to the CRS v4.0.0 milestone Apr 8, 2022
@dune73 dune73 added ⚠️ do not merge Additional work or discussion is needed despite passing tests and removed ⚠️ do not merge Additional work or discussion is needed despite passing tests labels Apr 8, 2022
@azurit
Copy link
Member
azurit commented May 7, 2022

@dune73 Can this be closed? Thanks.

@dune73
Copy link
Member Author
dune73 commented May 7, 2022

Absolutely. Thanks.

@dune73 dune73 closed this as completed May 7, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants
0