Skip to content
This repository has been archived by the owner on May 14, 2020. It is now read-only.

Monthly Chat Agenda November (2019-11-04) #1604

Closed
fzipi opened this issue Oct 22, 2019 · 1 comment
Closed

Monthly Chat Agenda November (2019-11-04) #1604

fzipi opened this issue Oct 22, 2019 · 1 comment

Comments

@fzipi
Copy link
Contributor

fzipi commented Oct 22, 2019

This is the Agenda for the Monthly CRS Chat.

The chat is going to happen on https://owasp.slack.com in the channel #coreruleset on Monday, November 4, at 20:30 CET.

Items on the Agenda:

PRs

Issues

Other items

Slack invite: https://join.slack.com/t/owasp/shared_invite/enQtNjExMTc3MTg0MzU4LWQ2Nzg3NGJiZGQ2MjRmNzkzN2Q4YzU1MWYyZTdjYjA2ZTA5M2RkNzE2ZjdkNzI5ZThhOWY5MjljYWZmYmY4ZjM

@dune73
Copy link
Contributor

dune73 commented Nov 4, 2019

Decisions

PRs

Issues

Other

  • @lifeforms reports from a call of the project leads with TW; namely the new manager of the ModSec project. TW is committed to solve the open issues with ModSec and bring it into a state where it passes our test suite. Performance will also be addressed, as will be the apache connector. They welcome our comments on github. This means we are invited to point out which issues / PRs we think deserve priority.
    On request of @airween, the following ModSec PRs have the highest priority. We have prioritized them together in this order:
  • Ruben van Vreeland presents securely.ai and gets a lot of applause
  • The CRS / ModSec meetup in Bern has attracted more than a dozen people on 2 of the 3 editions so far. The idea is now to continue in 2020 with 5 meetings. 4 different companies will host at least 1 of the meetups. Participants also stated they are open to do workshops where CRS issues are being handled.
  • We postpone the discussion on the semantic versioning (it's getting late)
  • Create SECURITY.md #1590 / security.md: We found a formula for the question what we consider a bug in CRS (a payload leading to unexpected behaviour of the WAF plus false negatives at PL4)

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

3 participants