16:30 <ratliff> #startmeeting
16:30 <meetingology> Meeting started Mon Apr  2 16:30:59 2018 UTC.  The chair is ratliff. Information about MeetBot at http://wiki.ubuntu.com/meetingology.
16:30 <meetingology> 
16:30 <meetingology> Available commands: action commands idea info link nick
16:31 <ratliff> The meeting agenda can be found at:
16:31 <ratliff> [LINK] https://wiki.ubuntu.com/SecurityTeam/Meeting
16:31 <ratliff> [TOPIC] Announcements
16:31 <ratliff> Thanks to Simon Quigley (tsimonq2) for providing debdiffs for xenial-artful for atril (LP: #1759069) and
16:31 <ratliff> debdiffs for trusty-xenial for kdepim (LP: #1698180)!
16:31 <ubottu> Launchpad bug 1759069 in atril (Ubuntu Artful) "[CVE] Arbitrary command injection via DVI filename injection when printing to PDF" [Medium,Fix released] https://launchpad.net/bugs/1759069
16:31 <ubottu> Launchpad bug 1698180 in kdepim (Ubuntu Xenial) "[CVE] Send Later with Delay bypasses OpenPGP" [High,Fix released] https://launchpad.net/bugs/1698180
16:32 <ratliff> Thanks to Ray Link (rlink) for providint the debdiff for xenial for xmltooling (LP: #1752306)!
16:32 <ubottu> Launchpad bug 1752306 in xmltooling (Ubuntu Artful) "Security bug in XMLTooling-C before 1.6.4 [CVE-2018-0489]" [Undecided,Incomplete] https://launchpad.net/bugs/1752306
16:32 <ratliff> or providing it, rather
16:32 <ratliff> Your work is very much appreciated and will keep Ubuntu users secure.
16:32 <ratliff> [TOPIC] Weekly stand-up report
16:33 <ratliff> jdstrand: you're up (if you are around)
16:33 <jdstrand> I'm here :)
16:33 <jdstrand> This week I plan to work on:
16:33 <jdstrand> - address conntrack deprecation issues in ufw for 18.04
16:33 <jdstrand> - apparmor upload to 18.04 to fix webbrowser-app and mediascanner2 upgrades
16:33 <jdstrand> - finish up miscellaneous updates branches for snapd
16:33 <jdstrand> - pick up the snap/usn notification work as have time
16:33 <jdstrand> that's it from me
16:34 <ratliff> thanks, jdstrand! m_deslaur is on national holiday today
16:34 <ratliff> sbeattie: you are up!
16:34 <sbeattie> I'm in the happy place this week
16:34 <sbeattie> I'm publishing openjdk packages this morning
16:34 <sbeattie> There should be kernel USNs to publish later this week, I believe.
16:35 <sbeattie> I'm still slowly making progress on my gcc retpoline backport for precise
16:35 <sbeattie> Between that and catching up on a weeks worth of email, that'll probably consume my week.
16:35 <sbeattie> that's it from me
16:36 <sbeattie> sarnold: I think you're up?
16:37 <sarnold> I'm on community this week; I'll start the MIRs with pysmi today, and keep on moving down the line
16:37 <sarnold> I'm leaning towards accepting openjpeg2; it's still got a long way to go :( but it's come so far and is probably a better jpeg2000 library than what we're already using
16:37 <sarnold> .. any comments about that would be welcome :)
16:37 <sarnold> that's it for me, uh .. leosilva?
16:38 <leosilva> I'm on bug triage
16:38 <leosilva> I'm hunting this week and researching cves.
16:38 <ratliff> tons of ruby CVEs about to land, leosilva
16:38 <leosilva> ratliff: I believe it's back to yo
16:38 <leosilva> \o/
16:38 <ratliff> I'm in the happy place this week.
16:39 <ratliff> My goal is to get the old kpi scripts checked into UCT along with some new kpi scripts and get all of the new kpis converted over to influx
16:40 <ratliff> Also a ton of internal work.
16:40 <ratliff> That's it for me.
16:40 <ratliff> [TOPIC] Highlighted packages
16:40 <ratliff> The Ubuntu Security team suggests that contributors look into merging Debian security updates in community-supported packages. If you would like to help Ubuntu but are not sure where to start, this is a great way to do so. See http://people.canonical.com/~ubuntu-security/d2u/ for available merges and https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures for details on preparing Ubuntu security updates. If you have any questions, feel
16:40 <ratliff> free to ask in #ubuntu-hardened. To find out other ways of helping out, please see https://wiki.ubuntu.com/SecurityTeam/GettingInvolved.
16:41 <ratliff> [TOPIC] Miscellaneous and Questions
16:41 <ratliff> Does anyone have any other questions or items to discuss?
16:42 <ratliff> Quick meeting this week!
16:43 <ratliff> We are seeing scattered reports of problems with the intel-microcode package. If you are experiencing any difficulties, please add your comments to LP #1760264
16:43 <ubottu> Launchpad bug 1759920 in linux (Ubuntu Artful) "duplicate for #1760264 intel-microcode 3.20180312.0 causes lockup at login screen(w/ linux-image-4.13.0-37-generic)" [High,Confirmed] https://launchpad.net/bugs/1759920
16:45 <ratliff> jdstrand, sbeattie, sarnold, leosilva: Thanks!
16:45 <ratliff> #endmeeting