You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
FINOS meetings involve participation by industry competitors, and it is the intention of FINOS and the Linux Foundation to conduct all of its activities in accordance with applicable antitrust and competition laws. It is therefore extremely important that attendees adhere to meeting agendas, and be aware of, and not participate in, any activities that are prohibited under applicable US state, federal or foreign antitrust and competition laws. Please contact legal@finos.org with any questions.
FINOS project meetings may be recorded for use solely by the FINOS team for administration purposes. In very limited instances, and with explicit approval, recordings may be made more widely available.
Review OSTIF Security Vulnerability Findings in Triage and Arrange Remediation
Multiple vulnerabilities reported by OSTIF and an independent user are in triage, including five highs and one critical.
@goldensyntax is preparing a remediation PR focused on input sanitisation.
Several related vulnerabilities (directory traversal, pack decompression, push approval bypass) are being triaged; some will be fixed together.
Maintainers lack sufficient permissions to handle vulnerability reports; @jescalada will forward relevant email threads to @kriswest for follow-up with FINOS to resolve access/configuration issues.
@jescalada will review and triage vulnerabilities, prioritising OSTIF-reported issues.
@dcoric: Finalise Postgres main feature PR and related sub-PR merges (completed).
@andypols: Review and resolve possible issues/clashes with push identity and UI changes; provide update at next meeting (completed).
@ALL: Prepare for discussion on using Git Proxy to govern wider GitHub/GitLab activity (completed).
@ALL: Continue to monitor and contribute to OSTIF vulnerability review as updates become available (clarified and rewritten; @jescalada to follow up as needed).
@goldensyntax: Submit PR to remediate critical directory traversal vulnerability; include input sanitisation.
@jescalada: Triaging and reviewing all OSTIF-reported security vulnerabilities; assist with switching push approvals to database IDs if feasible.
@fabiovincenzi: Review interim SSH vulnerability fix and provide feedback.
@kriswest: Follow up with FINOS (via @jescalada forward) regarding maintainer access/permissions for vulnerability reports.
@kriswest: Formalise and publish the project roadmap; review tools/process (e.g., Roadmapper).
@andypols: Write up specification and raise issue for improved SCM user identity fields and UI.
@jescalada: Complete patch releases for 2.0.1 and 2.1.1 post UI build path fix; ensure release branch protection.
@jescalada: Configure Dependabot rules to separately label CVE resolutions and evergreening PRs.
Date
20260907 - 4pm BST / 11am EDT
Meeting info
Meeting link
Register for future meetings
Meeting notices
FINOS Project leads are responsible for observing the FINOS guidelines for running project meetings. Project maintainers can find additional resources in the FINOS Maintainers Cheatsheet.
All participants in FINOS project meetings are subject to the LF Antitrust Policy, the FINOS Community Code of Conduct and all other FINOS policies.
FINOS meetings involve participation by industry competitors, and it is the intention of FINOS and the Linux Foundation to conduct all of its activities in accordance with applicable antitrust and competition laws. It is therefore extremely important that attendees adhere to meeting agendas, and be aware of, and not participate in, any activities that are prohibited under applicable US state, federal or foreign antitrust and competition laws. Please contact legal@finos.org with any questions.
FINOS project meetings may be recorded for use solely by the FINOS team for administration purposes. In very limited instances, and with explicit approval, recordings may be made more widely available.
Agenda
Meeting Minutes (7th September 2026)
Approve Past Meeting Minutes
Review OSTIF Security Vulnerability Findings in Triage and Arrange Remediation
Review Consolidated Summary of Git Proxy Roadmap Meeting and Actions
2.0.1 and 2.1.1 Patch Releases (post fix: broken UI build path fix: broken UI build path #1703)
2.2.0 Release Status
AOB, Q&A & Adjourn
Action Items