diff --git a/meeting-notes/2024-08-21.md b/meeting-notes/2024-08-21.md new file mode 100644 index 0000000..4345e72 --- /dev/null +++ b/meeting-notes/2024-08-21.md @@ -0,0 +1,19 @@ +# SRT meeting 2024-08-21 + +Previously: +https://github.com/haskell/security-advisories/blob/main/meeting-notes/2024-08-07 + +## Embargoed vulnerability work + +We provided a fix and we are coordinating the disclosure. + +## Call for Volunteers + +Jose wrote a draft to be communicated soon. + +## GitHub Action cabal-audit scan + +* Gautier has a minimal working version [GitHub Action](https://github.com/blackheaven/haskell-security-action) +* Some example: [here](https://github.com/blackheaven/vulnerable-sandbox/security/code-scanning/1) +* He made a [RFC](https://discourse.haskell.org/t/request-for-comments-github-haskell-security-action/10191) +* After discussing with MangoIV, Gautier will upstream the sarif file generation in `cabal-audit`