-
ErCiccione[m]
moneromooo: gitlab security release
-
moneromooo
Feel free to remind me from time to time, the repos have nothing new atm.
-
SerHack
ErCiccione[m]: I have already upgraded it. I've received an email that advised me about security vulnerabilities. Thank you
-
moneromooo
ty
-
selsta
moneromooo: Do you have access to patch for the Hackerone anonimal was talking about? If yes, can you PR it so that it gets reviewed?
-
selsta
Hackerone issue
-
ErCiccione[m]
serhack: oh you have access too now. Cool, so i don't have to ping mooo every time :)
-
moneromooo
Doesn't ring a bell. Let me check fire up that VM...
-
selsta
Apparently there is 1 outstanding report that has to get fixed and a patch for it exists already.
-
moneromooo
Do you know what it's about ?
-
selsta
no
-
selsta
but anonimal asked me for a release because it would get disclosed next month. So maybe it’s an older issue.
-
moneromooo
I think I know the one.
-
moneromooo
I see the patch.
-
moneromooo
vtnerd: did you see the patch for the ahook tor issue, and are you ok with it ?
-
selsta
v0.15.0.5 would be ready apart from this patch. So once the patch is ready and reviewed we can tag.
-
selsta
we can also wait a few more days
-
moneromooo
.5 already ?
-
selsta
yes, GUI is at .4 so next release would be .5
-
selsta
else it would not make sense
-
moneromooo
I just read the patch again, looks good to me. If no reply from vtnerd (it's within his expertise) I'll PR it soonish.
-
selsta
ok sounds good
-
vtnerd
no, I missed that one will look at it later today
-
vtnerd
oh that, yeah I review that and my only recommendation were updating the tests
-
moneromooo
OK, I'll PR it in the next couple hours hten. Thanks.
-
selsta
moneromooo: can you also open against v0.15 branch?
-
moneromooo
Oh. Sure.
-
moneromooo
done
-
selsta
ty, vtnerd can you also approve 6373
-
philkode
builds aren't signed by Fluffy anymore are they?
-
philkode
question answered in #monero, plz ignore
-
selsta
moneromooo: should we add #6251 to v0.15 release?
-
moneromooo
Sounds like a good idea.
-
selsta
vtnerd: you talked about fixing something before the next release on the coffee chat, can you PR that now or is it going to take some time?
-
selsta
we plan to tag tomorrow / Monday
-
vtnerd
uh I may have to re-listen to my own voice to remember what I was referencing
-
vtnerd
I was probably talkin about d++ which isn't going to be in that release anyway
-
selsta
I think it was related to anonymity networks where it fails silently or so.
-
vtnerd
ah yes, log sgp's complaint about logging when you have zero i2p and tor peers
-
vtnerd
I will try to work out something right now, it would be log statements only so the review shouldn't be too bad