<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>openstack/barbican — Stackers Network</title>
    <link>https://stackers.network/projects/openstack-barbican/</link>
    <atom:link href="https://stackers.network/projects/openstack-barbican/feed.xml" rel="self" type="application/rss+xml"/>
    <language>en</language>
    <lastBuildDate>Sat, 19 Sep 2026 00:00:00 +0000</lastBuildDate>
    <description>Weekly code-activity digest for openstack/barbican from Stackers Network.</description>
    <item>
      <title>openstack/barbican — Week of 2026-09-19</title>
      <link>https://stackers.network/projects/openstack-barbican/2026-09-19</link>
      <guid>https://stackers.network/projects/openstack-barbican/2026-09-19</guid>
      <pubDate>Sat, 19 Sep 2026 00:00:00 +0000</pubDate>
      <description>Crypto agility. The headline change extends the SimpleCrypto plugin's asymmetric key generation with crypto-agility support (~300 lines), broadening the algorithms and parameters the built-in plugin can produce rather than hard-coding a single scheme. See 985080. Security and…</description>
      <content:encoded><![CDATA[<p><strong>Crypto agility.</strong> The headline change extends the SimpleCrypto plugin's asymmetric key generation with crypto-agility support (~300 lines), broadening the algorithms and parameters the built-in plugin can produce rather than hard-coding a single scheme. See <a href="https://review.opendev.org/c/openstack/barbican/+/985080">985080</a>.</p>
<p><strong>Security and correctness.</strong> A BOLA/IDOR flaw in the consumer GET endpoints was closed, preventing cross-object access through the consumer lookup path. On the operator side, <code translate="no">barbican-manage</code> had its <code translate="no">logging.setup()</code> call reordered so early log output is captured correctly, and <code translate="no">db_manage.py</code> no longer injects the current working directory onto <code translate="no">sys.path</code> — a small but real hardening of the management tooling.</p>
<p><strong>Docs.</strong> Policy documentation received a broad typo and wording pass, and the KEK rotation guide was corrected to state that new keys must be <em>prepended</em> rather than appended during rotation — a meaningful semantic fix for anyone following the procedure. The mailing list link was also refreshed.</p>
<p><strong>Release plumbing.</strong> The stable/2026.2 branch was cut, with <code translate="no">.gitreview</code>, tox constraints, and master version markers updated in lockstep.</p>]]></content:encoded>
    </item>
  </channel>
</rss>
