====================================================================================== #wikimedia-office: ArchCom Security RFC meeting https://phabricator.wikimedia.org/E198 ====================================================================================== Meeting started by robla at 21:01:08 UTC. The full logs are available at https://tools.wmflabs.org/meetbot/wikimedia-office/2016/wikimedia-office.2016-06-01-21.01.log.html . Meeting summary --------------- * Please note: Channel is logged and publicly posted (DO NOT REMOVE THIS NOTE) | Logs: http://bots.wmflabs.org/~wm-bot/logs/%23wikimedia-office/ (robla, 21:01:36) * T123753 (robla, 21:09:11) * ACTION: robla propose a location for where reports go (robla, 21:10:24) * T135963 (robla, 21:15:17) * Please note: Channel is logged and publicly posted (DO NOT REMOVE THIS NOTE) | Logs: http://bots.wmflabs.org/~wm-bot/logs/%23wikimedia-office/ (robla, 21:22:04) * <gwicke> if there are no concerns about 0-4, then we could record that fact & start moving on those (no objections raised in response) (robla, 21:28:15) * <bawolff> Can we move to discussing stages 4-6 of rfc? [...] I'd like to know if anyone see's any major show stoppers (robla, 21:34:58) * bawolff asks if we can merge CSP code into MediaWiki, even if it isn't enabled. no objection seemed to be given (robla, 21:38:03) * <SMalyshev> CSP code meaning generating code or reporting code or both? <bawolff> meant both (robla, 21:40:01) * <bawolff> On the topic of retrospectives we were discussing earlier, for teams who have a specific extension they are responsible for, I think it would be nice to clarify their responsibilities for doing security releases of that extension (assuming its a non-bundled extension) (robla, 21:48:29) * LINK: https://phabricator.wikimedia.org/T135963 CSP RFC (robla, 21:49:39) * LINK: https://phabricator.wikimedia.org/T133735 (bawolff, 21:51:02) * LINK: https://phabricator.wikimedia.org/E203 <-next week's conversation (robla, 21:55:50) * next week's discussion T89331 Replace Tidy in MW parser with HTML 5 parse/reserialize (robla, 21:58:13) Meeting ended at 21:59:50 UTC. Action items, by person ----------------------- * robla * robla propose a location for where reports go People present (lines said) --------------------------- * bawolff (49) * robla (43) * brion (36) * gwicke (27) * TimStarling (23) * DanielK_WMDE__ (12) * jzerebecki (11) * SMalyshev (10) * stashbot (7) * dapatrick (6) * mutante (4) * Platonides (4) * Scott_WUaS (3) * wm-labs-meetbot` (3) * bd808 (2) * MaxSem (2) * subbu (1) * Matthew_ (1) * qgil (1) Generated by `MeetBot`_ 0.1.4