-
-
Notifications
You must be signed in to change notification settings - Fork 401
Monthly Chat Agenda June 2023 (2023-06-05 and 2023-06-19) #3221
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Comments
Decisions June 5th
🔵 Decision: Shift the dates to Sunday Nov 5th - Sunday Nov 12th
🔵 Decision: General agreement to change the project name at some future time. Next steps are: create a plan; talk with our communications/PR partner; continue the discussion inside the project.
🔵 Decision: No concrete plans from the CRS side at this time, but CRS is still open to providing financial support (and Coraza now have an advert out to find a developer for this project). Issue left open for further thought and discussion.
🔵 Decision: Agreed with @dune73's proposal: keep a short list of known bad scanners and lose the rest (could be a plugin in the future). @dune73 agreed to prepare the necessary PRs.
🔵 Decision: Wait until the end of the week and see if the word list issues are completed, as these are holding up the CRS v4 release.
🔵 Decision: General agreement. Focus on how much work it has taken to bring out CRS v4, and no time to complete a real 3.3.5 release. @RedXanadu agreed to write this.
🔵 Decision: Yes: add this in for RC 2 and see what happens.
🔵 Decision: Not discussed due to time constraints. To be considered before the next meeting. |
Decisions June 19
|
Uh oh!
There was an error while loading. Please reload this page.
This is the Agenda for the two Monthly CRS Chats.
The general chat is going to happen on https://owasp.slack.com in the channel #coreruleset on Monday, 2023-06-05, at 20:30 CET. That's the 1st Monday of the month. A separate issue chat is happening at the same location, same time on Monday, 2023-06-19. That's the 3rd Monday of the month. Please note that we have a CRS calendar (maintained by @fzipi).
Archived previous meetings and their decision are here.
What happened in the meantime since the chat last month
Outside development
Inside development
Rules
CRS Sandbox
Security
Plugins
Documentation and Public Relations
(If you're happy to do so, help us by liking/boosting our LinkedIn posts and our Twitter posts!)
Project Administration and Sponsor relationships
Tools
--wait-for...
flags)Testing incl. Seaweed and many future plans
Containers
CRS Status Page
Project discussions and decisions
OWASP ModSecurity Core Rule Set
toOWASP WAF Core Rule Set
or simply toOWASP Core Rule Set
by @fzipi. This will be more in line that we support other engines.Coraza/libcoraza: Should the CRS project pay for someone to build an Nginx connector?
PR feat: scanner overhaul: new rules, new data files #3202
ssrf.data
andjava-classes.data
#3219: Do we want to include 127.0.0.1 and friends into the into ssrf rule?Rules development, key project numbers
PRs that have been merged since the last meeting
web-shells-php.data
#3215sql-errors.data
#3214restricted-files.data
#3212We merged 9 PRs since the last monthly project chat.
Open PRs marked DRAFT or work in progress or needs action
ssrf.data
andjava-classes.data
#3219Open issues and PRs
Separate 2nd Meeting (Monday, 2023-06-19)
This is the last major rules construction site before we can tackle the release candidate.
How to get to our slack and join the meeting?
If you are not yet on the OWASP Slack, here is your invite: https://owasp.org/slack/invite .
Everybody is welcome to join our community chat.
The text was updated successfully, but these errors were encountered: