StackStorm / community

Async conversation about ideas, planning, roadmap, issues, RFCs, etc around StackStorm
https://stackstorm.com/
Apache License 2.0
8 stars 3 forks source link

TSC Meeting (12 Dec 2023) - v3.8.1 patch release progress, v3.9.0 release plans, ST2-K8s security #129

Closed arm4b closed 4 months ago

arm4b commented 6 months ago

December 2023 @StackStorm/tsc 1 hour meeting:

Meeting Agenda

v3.8.1 Release Progress (finalizing)

StackStorm Contributors and Maintainers

StackStorm v3.8.1 patch release wouldn't be possible without our opensource community who listened when we asked for help and stepped in to assist: fixing broken builds, updating dependencies, security, testing. Let's highlight volunteers, contributors and maintainers who were active recently or helped with the v3.8.1 patch release and upcoming v3.9.0.

Starting strong with the community-driven v3.8.1, there's much more work that needs to be done for the upcoming bigger v3.9!

v3.9.0 Release Planning

Adding automated security scan for stackstorm-k8s

Requested by @ZoeLeah to add security scan like like Snyk to raise awareness around StackStorm K8s/Docker security, its components and builds.

ZoeLeah commented 6 months ago

We use Snyk not only for scanning stackstorm-k8s, but for all repositories of StackStorm that we use. Here is some information about Snyk and how you can register open source software for free: https://snyk.io/de/open-source-projects/

ZoeLeah commented 6 months ago

If it's not too late, I would like to add another item to the agenda. SonarCloud: https://www.sonarsource.com/products/sonarcloud/

arm4b commented 6 months ago

Meeting Minutes

Attendees

@ZoeLeah, @winem, @rush-skills, @dalesmith, Ravi, Scott, Wilson, @amanda11, @armab

v3.8.1 patch release progress

Contributors, Maintainers and Adopters

New Adopters:

v3.9.0 Plans

Project - https://github.com/orgs/StackStorm/projects/31/views/1 TSC decided to ship the following in the upcoming v3.9.0:

Snyk (security checks) and SonarCloud (linting, static analysis) integrations