February 5, 2025
Participants: Dan Janowski, @varnerac, Lee Barney, @maennchen, @voltone, Marc Nickert, Michael Lubas, Paul Swartz, Bas Wegh, @kiko
Compliance updates
CNA (CVE Numbering Authority)
- Still pending a response from MITRE
- Proposed meeting slots in February approaching
CISA Self Attestation and NIST SSDF
- To be discussed in call with NIST
- Some uncertainty about whether EEF can do this on behalf of projects
OpenChain
- Erlang/OTP certified (see @kiko’s announcement)
- Working on Elixir and Gleam
- Source SBOM
- Policies
Source SBoM of OTP
- Contributions to OSS Review Toolkit accepted
- Source SBOM will be published with OTP releases starting with OTP 28
- Working on splitting SBOM by application
Application for Supply Chain Funding
- Trying to obtain funding for ongoing supply chain work
- Next step: align with documented package manager best-practices
- Get hex.pm involved, as well as build tools (Mix, Rebar3)
Erlang distribution protocol hardening
- Picking up discussion started in Slack
- Initial idea (Dan): make it easier to secure with TLS out of the box
- Issuing certificates
- Injecting kernel parameters
- Broader use-cases (Lee): connecting (possibly transient) nodes across the Internet
- Instead of having to go through e.g. HTTPS
- Large clusters, frequent membership changes, unreliable nodes
- Security aspects just one part of it
- Invited Lee to present his work to the group in the future
- Offered Dan support with first round of research into possible approaches
Other updates
PenTest Sample App
- Michael just finished pen-testing Oban Pro, might be interested
- Need to start collecting requirements for the app’s scope
- Take it to Slack or Notion (see below)
WG collaboration tooling
- We have access to Notion, with non-profit discounts
- Read-only access is free, must pay per write-enabled seat
- Currently being used by @maennchen for broader EEF work
- Open it up a bit, start linking from Slack and meeting notes
- Create a landing page for the WG
- Keep licensed seats at a minimum
Next meeting
Wed 5 March 2025 at 16:00 CET / 15:00 GMT / 10am EST / 7am PST / 0:00 (Thu) JST