Sonatype discussion
Description
Confluence content
mentioned on
- https://wiki.onap.org/pages/viewpage.action?pageId=45301133
- https://wiki.onap.org/pages/viewpage.action?pageId=48529728
- https://wiki.onap.org/pages/viewpage.action?pageId=48529742
- https://wiki.onap.org/pages/viewpage.action?pageId=48532390
- https://wiki.onap.org/pages/viewpage.action?pageId=48532393
- https://wiki.onap.org/pages/viewpage.action?pageId=50203577
- https://wiki.onap.org/pages/viewpage.action?pageId=53248265
Activity
Former user May 3, 2019 at 12:18 AM
I'm going to close this as there will be no action taken from the vendor on this.
RelEng created an LDAP group awhile ago to give developers access to the NexusIQ info.
Community members just open a helpdesk ticket asking to be added to the "nexus-iq-onap-devs" group.
We can share the info with the other orgs as long as we are working directly with their security teams.
-kenny
Former user February 19, 2019 at 1:13 PMEdited
@Former user - in addition to @Amy Zwarico's request, I have deferred this ticket to El-Alto based on TSC Call (2/14/2019). Path to move forward: Creation of single group including committers. This request will be implemented at the same time than CLA Enforcement. For Dublin, we will proceed as we did for Casablanca.
Amy Zwarico February 14, 2019 at 2:32 PM
Please ask Sonatype if we can share the NexusIQ scan results related to ODL with the ODL team.
Former user January 24, 2019 at 1:30 AM
Reviewed status with one of our internal application teams regarding an alternate solution proposed before the break. Met on this Tuesday. Suggested solution only provides library traceability based upon know CVEs - No direct code analysis. Dead-end.
Sent an email to Sonatype earlier to set up a meeting.
Former user January 4, 2019 at 10:12 AM
Currently rescheduled to the next TSC call - January 10th, 2019
As a follow-up from TSC call (12/6), Kenny took the action to discuss with Sonartype people about the concers we raised using NexusIQ.
Readout expected no later than F2F meeting in Paris
Stretch goal: 2019/1/3