SQL Injection in FilterEngine Oracle JSON Path via DID Search API (GHSA-vjr5-c9qv-hgm3, CVE-2026-29080)
Only ATLAS & CMS affected, hotfixed in the last weeks
SQL Injection in External PostgreSQL Metadata Plugin via DID Search API (GHSA-6j7p-qjhg-9947, CVE-2026-29090)
Affects the EXTERNAL postgres metadata plugin
Fixed in
35 LTS -> 35.8.5
38 LTS -> 38.5.5
39 -> 39.4.2
40 -> 40.1.1
Please update!
No meeting next week (Ascension day)
15:05
→
15:25
Community News & DevOps roundtable20m
ATLAS
CMS
Fermilab
DUNE
PgBouncer deployed on production
Will set up another development instance for the purpose of testing the Rucio/Globus integration
Deletion from tape RSE (Q on Mattermost)
Removal of the replica with SQL is not recommended; maybe update the replica paths instead?
ePIC
INFN Datalake
RI-SCALE
TPC transfers with OIDC and WebDAV successfully demonstrated
CTAO
MADDEN
IHEP
15:25
→
15:55
Developers roundtable30m
Reflection about ongoing Sprint 2 (Sprint Board) [Ben]
‘Reporting on the current Rucio sprint, in case my internet breaks off again: There is little planned this sprint, some replies that they do not have time, others I don't really know. What was planned for the sprint seems to be on-track and worked on.’