8000 Monthly Chat Agenda September 2023 (2023-09-04 and 2023-09-18) · Issue #3279 · coreruleset/coreruleset · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

Monthly Chat Agenda September 2023 (2023-09-04 and 2023-09-18) #3279

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
dune73 opened this issue Aug 8, 2023 · 2 comments
Closed

Monthly Chat Agenda September 2023 (2023-09-04 and 2023-09-18) #3279

dune73 opened this issue Aug 8, 2023 · 2 comments

Comments

@dune73
Copy link
Member
dune73 commented Aug 8, 2023

Monthly Chat Agenda September 2023 (2023-09-04 and 2023-09-18)

This is the Agenda for the two Monthly CRS Chats.

The general chat is going to happen on https://owasp.slack.com in the channel #coreruleset on Monday, 2023-09-04, at 20:30 CET. That's the 1st Monday of the month. A separate issue chat is happening at the same location, same time on Monday, 2023-09-18. That's the 3rd Monday of the month. Please note that we have a CRS calendar (maintained by @fzipi).

Archived previous meetings and their decision are here.

What happend in the meantime since the chat last month

Outside development

Inside development

Rules

  • Only a handful of rule fixes / keyword list updates remain for CRS v4 release candiate, but we have a hard time solving them

CRS Sandbox

  • See discussion about supported version below

Security

  • 2 open security items. None of them is new.

Plugins

  • FIXME: Please fill in

Documentation and Public Relations

  • 📝 The project to rework the INSTALL documentation carries on slowly.
  • Blocked dev portraits are being finished as we speak
  • Draft project renaming document is being overhauled before presentation to devs
  • 🔁 A welcome proposal to sync the 'Contributing Guidelines' across repos using GitHub actions feat: auto-sync to coreruleset/documentation #3292.

Project Administration and Sponsor relationships

  • Dev Retreat in Budapest (Nov 5 - Nov 12) preparations are coming along. Participants number around the same size.
  • One SILVER sponsor upgraded to GOLD, other sponsor talks are dragging along
  • Renewal talks are happening with existing sponsors

Tools

  • FIXME: Please fill in

Testing incl. Seaweed and many future plans

Containers

  • Released container with CRS version 3.3.5.

CRS Status Page

  • Postponed until after CRSv4.

Project discussions and decisions

Rules development, key project numbers

PRs that have been merged since the last meeting

We merged 4 PRs since the last monthly project chat.

Open PRs

Open PRs marked DRAFT or work in progress or needs action

Open issues and PRs

  • As of Monday, we have 111 open issues.
  • As of Monday, we have 11 open pull requests.

Separate 2nd Meeting (Monday, 2023-09-17)

How to get to our slack and join the meeting?

If you are not yet on the OWASP Slack, here is your invite: https://owasp.org/slack/invite .

Everybody is welcome to join our community chat.

@dune73 dune73 changed the title Monthly Chat Agenda September 2023 (2023-09-03 and 2023-09-17) Monthly Chat Agenda September 2023 (2023-09-04 and 2023-09-18) Sep 3, 2023
@franbuehler
Copy link
Contributor
franbuehler commented Sep 4, 2023

Decisions September 4th

⏳ CRS sandbox: Working with version numbers: unclear behavior, non-documented features etc. (Also https://github.com/coreruleset/crs-sandbox/issues/67)

  • 🔵 Decision: @theMiddleBlue self assigned the linked issue and will implement this in the next few weeks.

📝 Issue #3288 ("Rule 932260 false positive with "scheduledAt" keyword")

❓ The complex of PRs and issues around #3189, #3190 and #3276.

🎉 Prepare dev retreat topics

@franbuehler
Copy link
Contributor
franbuehler commented Sep 18, 2023

Decisions September 18th

🎉 We merged a huge PR by @theseion today: #3276

💻 CRS v4.0

  • 🔵 Decisions:
    • We would like to do a feature freeze at the end of the month (Sep 30) and to try to do RC2 in Mid-October. Full release before the retreat is probably too aggressive. But maybe November.
    • We'll use the label v4 to mark issues or PRs that should go into this major release.

#3304 - Do we want to fix this FP in general or do we add this fix to the new Roundcube exclusion plugin only?

#2373 - initcol actions must run before plugin configuration

  • Problem: The rules in the *-config.conf and *-before.confg files are read before 901-INITIALIZATION. DoS rules should run and to block as early as possible -> *-after would be stupid.
  • 🔵 Decision: @theseion with help of @dune73 and @airween will try to check for initcol. If the collection is initialized by the plugin -> remove the 901 rule via ctl statement and do initcol yourself.

👩‍💻 #3184 - base64decode woes. We should take over the PR. Should we use t:jsDecode on all Javascript rules or just Node.js rules?

  • 🔵 Decision: @RedXanadu will work on this, sort it out and maybe provide some performance numbers (we're not sure if this has a performance impact). @theseion will help with JS.

📦 Dependencies for issues and PRs

  • 🔵 Info by Max: In PRs you can now create dependencies. A dependency means that an additional merge check will prevent merges until the dependency has been resolved. To declare a dependency you have to mention it in the PR description (aka the first comment). For example depends on #4. The link can point to either a PR or an issue, so PRs can be dependent on issues. This also works when the dependency is added later by editing the PR description.

3 additional infos:

  • OWASP published the candidates for the board elections in October. OWASP members should execute their right to vote.
  • We have 2 drafts for the release poster. We'll share with devs once it's a reasonable quality.
  • Info by @airween: We have approximately two weeks to finalise number of participants in Budapest retreat. 5th of October is the last date when we can modify the number. After that we lost some money if we decrease the amount, but we can increase it later.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants
0