Automatic Updates Initiative meeting on Apr 18, 2023

Created on 5 April 2023, over 1 year ago
Updated 26 May 2023, over 1 year ago

Transcript

0️⃣ Who is here today? Comment in the thread below to introduce yourself and tell us why you are joining us.

1️⃣ Do you have any topics to propose for the meeting today? Feel free to propose them in this thread, and then I will give them their own unique threads for discussion. Conversation moving slow? Go ahead and open your own thread in the next numeric order.

2️⃣ Hashed Bin Support progress

2️⃣ 1️⃣ Server side (Rugged) - https://gitlab.com/rugged/rugged/-/issues/99 (edited) 

2️⃣ 2️⃣ Client side (php tuf) - https://github.com/php-tuf/php-tuf/pull/335 (edited) 

3️⃣ Core signing@drumm has worked out a system to use satis to create a new packages.d.o endpoint that has signed data. When this endpoint is used, the data overrides the default data from github.The plan is written up here: #3352216: Securely sign Drupal core packages, even though they are hosted on GitHub/packagist directly  (edited) 

4️⃣ 'Productionizing' the container stack.@nnewton has recruited some additional help from another team member.

5️⃣ Cron Updates in the contrib module(and eventually core)As part of Enable unattended updates @pwolanin (he/him) asked for a drush or console command to run cron updateswhich resulted in Add command to allow running cron updates via console and by a separate user, for defense-in-depthI am currently working on a drush command for this but it would probably be symfony console command in core.We have open question for @pwolanin (he/him) to see if drush cron would be good enough in the short term.The benefit of this of having some command would be that the codebase would not have to writeable from the web server.  @dww and @catch have been stressing the importance of this in Add Alpha level Experimental Package Manager module

📌 Task
Status

Fixed

Version

2.0

Component

Meetings

Created by

🇺🇸United States hestenet Portland, OR 🇺🇸

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Production build 0.71.5 2024