)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"596f47ad0ef9fff293328d1531649b21aa4450db","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"50efe121_a45ebc02","updated":"2026-05-06 14:12:25.000000000","message":"Looks like this will need to take OSSA-2026-011","commit_id":"19574726dd7ee1012cb1d16bf168b2330bda0c5f"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"c40512a3674126d663f862544670fc4d30069538","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"98973166_ca4c25a8","updated":"2026-04-30 20:02:54.000000000","message":"cid: Thanks for getting this in.. since this will be WIP for a bit, Use workflow -1 please","commit_id":"19574726dd7ee1012cb1d16bf168b2330bda0c5f"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"de5af9f9b03e25371c5e15764e8a9d32cc37f02d","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"7afe872c_387b5360","in_reply_to":"50efe121_a45ebc02","updated":"2026-05-06 20:23:14.000000000","message":"or more :) best to leave it OSSA-2026-pending perhaps until we\u0027re ready","commit_id":"19574726dd7ee1012cb1d16bf168b2330bda0c5f"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"77272e218ae3aa54be2e9c85a87b8398620ddeb6","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":4,"id":"0e74249a_2da5751f","in_reply_to":"7afe872c_387b5360","updated":"2026-05-06 20:23:49.000000000","message":"(didn\u0027t mean to set \"resolved\")","commit_id":"19574726dd7ee1012cb1d16bf168b2330bda0c5f"}],"ossa/OSSA-2026-022.yaml":[{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"d1fe636bb54ce60423ab3d9ce201def7dbcaa7e4","unresolved":true,"context_lines":[{"line_number":42,"context_line":""},{"line_number":43,"context_line":"reviews:"},{"line_number":44,"context_line":"  2026.2/hibiscus (development):"},{"line_number":45,"context_line":"    - https://review.opendev.org/c/openstack/ironic-python-agent/+/987391"},{"line_number":46,"context_line":""},{"line_number":47,"context_line":"  2026.1/gazpacho:"},{"line_number":48,"context_line":"    - https://review.opendev.org/c/openstack/ironic-python-agent/+/993016"}],"source_content_type":"text/x-yaml","patch_set":5,"id":"2835c7a4_dc7b75a5","line":45,"updated":"2026-06-15 21:11:28.000000000","message":"There should be bugfix branch patches; I can\u0027t find them. I have an ask out to Clif about it.","commit_id":"f458a73baa616c36b737c02089e1d95b1f43b4f5"}],"ossa/OSSA-2026-024.yaml":[{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"d1c0cf17f60c5b7b9adf34e09c7f19fef57ff160","unresolved":true,"context_lines":[{"line_number":16,"context_line":""},{"line_number":17,"context_line":"  The practical impact is limited; the attacker needs the ability to supply a"},{"line_number":18,"context_line":"  partition image for bare-metal deployment and at the point of exploitation,"},{"line_number":19,"context_line":"  IPA holds only an outdated agent_token and a heavily redacted node object."},{"line_number":20,"context_line":""},{"line_number":21,"context_line":"  Whole disk images are not affected and partition images that include their"},{"line_number":22,"context_line":"  own EFI boot artifacts at /boot and /efi are not also affected as Ironic"}],"source_content_type":"text/x-yaml","patch_set":9,"id":"ef50dbaf_919f0e85","line":19,"range":{"start_line":19,"start_character":20,"end_line":19,"end_character":40},"updated":"2026-06-16 14:49:11.000000000","message":"So, its valid when executed, but only allows a heartbeat to be recorded in Ironic\u0027s API.","commit_id":"ab3dbcd7090c1a7b6d95bbf088c9ed6776e28b38"},{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"f2e5792e0bebf5df9635c368c9995d6b29a910de","unresolved":true,"context_lines":[{"line_number":16,"context_line":""},{"line_number":17,"context_line":"  The practical impact is limited; the attacker needs the ability to supply a"},{"line_number":18,"context_line":"  partition image for bare-metal deployment and at the point of exploitation,"},{"line_number":19,"context_line":"  IPA holds only an outdated agent_token and a heavily redacted node object."},{"line_number":20,"context_line":""},{"line_number":21,"context_line":"  Whole disk images are not affected and partition images that include their"},{"line_number":22,"context_line":"  own EFI boot artifacts at /boot and /efi are not also affected as Ironic"}],"source_content_type":"text/x-yaml","patch_set":9,"id":"632fa768_7b9e603b","line":19,"range":{"start_line":19,"start_character":20,"end_line":19,"end_character":40},"in_reply_to":"b77b5360_aafd012e","updated":"2026-06-16 17:56:08.000000000","message":"Julia and I talked about this in a video call, the wording isn\u0027t 100% accurate but is generally reflective of what\u0027s going on and is OK.","commit_id":"ab3dbcd7090c1a7b6d95bbf088c9ed6776e28b38"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"f16ca157ddbcb45732f146c8566c1cd52784ba7a","unresolved":true,"context_lines":[{"line_number":16,"context_line":""},{"line_number":17,"context_line":"  The practical impact is limited; the attacker needs the ability to supply a"},{"line_number":18,"context_line":"  partition image for bare-metal deployment and at the point of exploitation,"},{"line_number":19,"context_line":"  IPA holds only an outdated agent_token and a heavily redacted node object."},{"line_number":20,"context_line":""},{"line_number":21,"context_line":"  Whole disk images are not affected and partition images that include their"},{"line_number":22,"context_line":"  own EFI boot artifacts at /boot and /efi are not also affected as Ironic"}],"source_content_type":"text/x-yaml","patch_set":9,"id":"b77b5360_aafd012e","line":19,"range":{"start_line":19,"start_character":20,"end_line":19,"end_character":40},"in_reply_to":"ef50dbaf_919f0e85","updated":"2026-06-16 14:49:47.000000000","message":"Oh, and it gets invalidated as soon as the deploy completes, i.e. in the very next step or two.","commit_id":"ab3dbcd7090c1a7b6d95bbf088c9ed6776e28b38"}]}
