Skip to content

7th Sept 2026 - GitProxy Meeting Minutes #1711

Description

@kriswest

Date

20260907 - 4pm BST / 11am EDT

Meeting info

Meeting notices

  • FINOS Project leads are responsible for observing the FINOS guidelines for running project meetings. Project maintainers can find additional resources in the FINOS Maintainers Cheatsheet.

  • All participants in FINOS project meetings are subject to the LF Antitrust Policy, the FINOS Community Code of Conduct and all other FINOS policies.

  • FINOS meetings involve participation by industry competitors, and it is the intention of FINOS and the Linux Foundation to conduct all of its activities in accordance with applicable antitrust and competition laws. It is therefore extremely important that attendees adhere to meeting agendas, and be aware of, and not participate in, any activities that are prohibited under applicable US state, federal or foreign antitrust and competition laws. Please contact legal@finos.org with any questions.

  • FINOS project meetings may be recorded for use solely by the FINOS team for administration purposes. In very limited instances, and with explicit approval, recordings may be made more widely available.

Agenda

Meeting Minutes (7th September 2026)

  • Approve Past Meeting Minutes

  • Review OSTIF Security Vulnerability Findings in Triage and Arrange Remediation

    • Multiple vulnerabilities reported by OSTIF and an independent user are in triage, including five highs and one critical.
    • @goldensyntax is preparing a remediation PR focused on input sanitisation.
    • Several related vulnerabilities (directory traversal, pack decompression, push approval bypass) are being triaged; some will be fixed together.
    • Maintainers lack sufficient permissions to handle vulnerability reports; @jescalada will forward relevant email threads to @kriswest for follow-up with FINOS to resolve access/configuration issues.
    • @jescalada will review and triage vulnerabilities, prioritising OSTIF-reported issues.
    • @fabiovincenzi to review SSH vulnerability fix.
    • @jescalada to investigate the feasibility of switching to database-generated IDs for push approvals to address replay vulnerabilities.
  • Review Consolidated Summary of Git Proxy Roadmap Meeting and Actions

    • @kriswest presented a summary of the recent roadmap meeting (26th August 2026 - GitProxy Roadmap meeting Minutes #1702).
    • High-priority roadmap items:
      • Event hooks & notification system
      • Plugin system extensions
      • Supply chain security (CVEs, dependency updates, TLS/SSL support)
    • UI accessibility improvements are progressing, led by @goldensyntax.
    • Database adapter for PostgreSQL and TLS support targeted for 2.2.0.
    • More maintainers are needed to accelerate PR reviews, especially from Citi and G-Research.
    • Roadmap needs to be formalised and published; @kriswest will investigate the process and tools (e.g., Roadmapper).
  • 2.0.1 and 2.1.1 Patch Releases (post fix: broken UI build path fix: broken UI build path #1703)

  • 2.2.0 Release Status

    • The primary blocker for 2.2.0 is external review of the consolidated PostgreSQL feature PR.
    • @dcoric and @fabiovincenzi completed PR consolidation; review by non-GR maintainers is needed.
    • Security fixes will be included in 2.2.0 once ready, but not listed in the public milestone as per responsible disclosure.
  • AOB, Q&A & Adjourn

    • Discussed Dependabot configuration improvements (separating CVE resolutions from evergreening) to streamline prioritisation.
    • Recording policy reiterated: transcript is used for minutes, recording is deleted unless explicit permission is sought.
    • No other business raised.

Action Items

  • @Andreybest: Submit initial PR for TS REST API documentation/control; review and iterate.
  • @ALL: Recruit additional maintainers/reviewers, especially from G-Research and Citi, to accelerate PR review.
  • @kriswest: Follow up with FINOS and Andy Block (Red Hat) for OpenSSF/OSSF partnership opportunity.
  • @ALL: Review pre-commit.com for possible hook/process reuse or integration.
  • @ALL: Volunteers needed to test SSL support in the UI (see @andypols request).
  • @fabiovincenzi / @dcoric: Review and refactor duplicated diff/log storage; ensure no breaking change for old pushes.
  • @ALL: Review and approve governance update PR docs: add Technical Charter and restructure governance documentation #1664; request input from other maintainers (@coopernetes, @grovesy).
  • @ALL: Provide external review of consolidated PostgreSQL feature PR (targeting 2.2.0 release).
  • @jescalada: Follow up with FINOS events team for OSFF New York booth logistics and content updates (completed).
  • @jescalada: Raise issue and review changes in PR feat(proxy): resolve push identity from token via SCM provider API #1604 (push identity); update architecture docs (completed).
  • @dcoric: Finalise Postgres main feature PR and related sub-PR merges (completed).
  • @andypols: Review and resolve possible issues/clashes with push identity and UI changes; provide update at next meeting (completed).
  • @ALL: Prepare for discussion on using Git Proxy to govern wider GitHub/GitLab activity (completed).
  • @ALL: Continue to monitor and contribute to OSTIF vulnerability review as updates become available (clarified and rewritten; @jescalada to follow up as needed).
  • @goldensyntax: Submit PR to remediate critical directory traversal vulnerability; include input sanitisation.
  • @jescalada: Triaging and reviewing all OSTIF-reported security vulnerabilities; assist with switching push approvals to database IDs if feasible.
  • @fabiovincenzi: Review interim SSH vulnerability fix and provide feedback.
  • @kriswest: Follow up with FINOS (via @jescalada forward) regarding maintainer access/permissions for vulnerability reports.
  • @kriswest: Formalise and publish the project roadmap; review tools/process (e.g., Roadmapper).
  • @andypols: Write up specification and raise issue for improved SCM user identity fields and UI.
  • @jescalada: Complete patch releases for 2.0.1 and 2.1.1 post UI build path fix; ensure release branch protection.
  • @jescalada: Configure Dependabot rules to separately label CVE resolutions and evergreening PRs.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions