13:55:21 <kennypaul>#startmeeting tsc 2017-01-1113:55:21 <collabot> Meeting started Thu Jan 11 13:55:21 2018 UTC. The chair is kennypaul. Information about MeetBot at http://wiki.debian.org/MeetBot.
13:55:21 <collabot> Useful Commands: #action #agreed #help #info #idea #link #topic.
13:55:21 <collabot> The meeting name has been set to 'tsc_2017_01_11'
13:55:31 <kennypaul>#chair phrobb13:55:31 <collabot> Current chairs: kennypaul phrobb
13:55:41 <kennypaul>#topic rollcall13:58:05 <alla_>#info Alla Goldner, Amdocs14:00:24 <frankbrockners>#info Frank Brockners14:00:28 <amir_levy>#info Amir Levy Cloudify14:00:48 <cdonley>#info Chris Donley Huawei14:00:49 <RannyHaiby>#info Ranny Haiby, Nokia14:01:21 <rajeshgadiyar>#info Rajesh Gadiyar Intel14:02:40 <jamil>#info jamil for Orange14:02:42 <xinhuili>#info xinhui li, VMware14:02:43 <JasonHunt>#info Jason Hunt, IBM14:03:08 <ningso>#info Ning So, Reliance Jio14:03:54 <gilbert>#info mazin14:03:58 <kennypaul>#info Lingli Deng, CMCC14:04:12 <Zhaoxing>#info Zhaoxing Meng, ZTE14:06:07 <SteveT>#info Stephen Terrill, Ericsson14:09:05 <kennypaul>#topic Security recommendations14:09:07 <phrobb>#topic Security Subcommittee Readout14:10:37 <phrobb>#info SteveT explains the static scanning and the build-time dependency scanning that is possible14:11:04 <phrobb>#info 2 proposals for each of these types of scanning14:12:11 <phrobb>#info for Static scanning, the committee recommends Coverity. It looks to be good enough to begin with for the project. The recommendation is to have a weekly scan via Coverity and the result will be provided to the PTLs14:12:53 <phrobb>#info the committee needs help from LF to deliver scan reports to PTLs14:14:05 <DhananjayPavgi>#info Dhananjay Pavgi, Tech Mahindra14:14:06 <phrobb>#info New release cycle requirements - M3 No high level vulnterabilities and M4 No high or medium level vulnerabilities14:16:27 <frankbrockners> FYI - many projects use coverity https://scan.coverity.com/projects
14:16:43 <frankbrockners> see e.g. for OpenDaylight: https://scan.coverity.com/projects/opendaylight
14:17:42 <frankbrockners> or FD.io/VPP: https://scan.coverity.com/projects/fd-io-vpp
14:21:57 <kennypaul>#info discussion over whether to start scans w/ Amsterdam or Beijing14:23:31 <kennypaul>#info request is also for LF to integrate coverity scan into ci/cd14:24:01 <kennypaul>#info administration will be required on the part of the community14:24:28 <Susana_>#info Susana Sabater, Vodafone14:24:44 <kennypaul>#action kennypaul submit ticket for coverity scanning14:25:56 <kennypaul>#info request for nexus-iq scanning be made available to the PTLs14:26:47 <kennypaul>#info LF ready to open the reports to PTLs14:29:35 <kennypaul>#agreed the requests outlined in the presentation materials will be adopted14:33:46 <kennypaul>#info request the LF will check on the ability to open up nexus to community.14:34:27 <kennypaul>#info request ability for community to make manual runs14:35:22 <kennypaul>#action Pam to submit a ticket, cc kenny and phil14:35:49 <kennypaul>#topic Release Status14:36:16 <kennypaul>#info gildaslanilis reviewed his slides14:39:46 <kennypaul>#link https://wikilf-onap.onapatlassian.orgnet/wiki/display/DW/Beijing+Release+Platform+Maturity14:41:06 <kennypaul>#action PTLS for projects that have not updated above link must provide status by toimorrow.14:42:29 <nagu>#info nagaraja sr, Infosys14:46:09 <kennypaul>#info discussion of Music project14:46:57 <kennypaul>#info does project proposal align with OOM.14:47:03 <kennypaul> ?
14:48:03 <kennypaul>#info There is overlap w/ OOM14:55:09 <kennypaul>#info key players on OOM are unavailable14:59:16 <kennypaul>#info certificate and secret management agreed to be part of AAF14:59:39 <kennypaul>#info integration team blocked by a couple of bugs15:01:20 <kennypaul>#action meeting w/ following people regarding music/oom15:01:44 <kennypaul>#info m.a.choquette@bell.ca??david.sauvageau@bell.ca??Roger.Maitland@amdocs.com??Mike.Elliott@amdocs.com??Mandeep.Khinda@amdocs.com??frank.obrien@amdocs.com??alla.goldner@amdocs.com??gildas.lanilis@huawei.com15:03:26 <kennypaul>#topic Functional Requirements15:03:50 <kennypaul>#info Alla Goldner reviewed the slides15:05:28 <kennypaul>#info (OOM/Music) Also jh245g@att.com for meeting15:06:53 <kennypaul>#info HFA in best shape15:11:07 <kennypaul>#info likely 3-4 will be ready by next week.15:11:30 <kennypaul>#info focusing efforts on those15:13:56 <kennypaul>#info likely requirements are HPA, Change Management, Auto scaling, Manul scaling, PNF15:14:40 <kennypaul>#topic integrtation15:14:54 <kennypaul>#info bl;ocked as mentioned before15:15:54 <kennypaul>#topic Arch recommendations15:16:37 <kennypaul>#info cdonley reviewed the slides15:18:33 <kennypaul>#info #info asking teams to focus on documentation of apis15:19:15 <kennypaul>#info standardise on swagger for api doc15:21:43 <kennypaul>#info asking teams to standard on console for kv stores15:22:35 <kennypaul>#info use common libs & services15:23:43 <kennypaul>#info arch team will review progress @ M315:23:46 <gildaslanilis>#info Meeting for OOM and Music is scheduled to meet on Jan 11 for 11 am PST zoom ID: 22 29 35 56 4415:25:03 <kennypaul>#info few outstanding components for containers, but all in containers is the goal15:26:14 <kennypaul>#ingo discussion around M1 checklist15:26:55 <kennypaul>#info chris is expecting teams will have a few jira tickets opened as part of M1 delivery.15:27:49 <kennypaul>#info M1 template will be modified going forward.15:31:39 <kennypaul>#topic upcoming meetings15:33:02 <kennypaul>#info next week's meeting till be 2 hrs to accomodate M1 reviews15:33:28 <kennypaul>#info all PTLs or a proxy are required next week15:34:13 <kennypaul>#info SteveT project scope to be moved to jan 25.15:34:20 <kennypaul>#endmeeting
...
Zoom Chat Log
Anchor
zoom
zoom
06:05:37 From Alla Goldner : I think we agreed on dates for oNS collocated meeting 06:05:41 From Alla Goldner : march 25-27 06:08:01 From Mazin : Yes. Phil is looking for space. 06:08:57 From Mazin : The TSC meeting will probably happen on Sunday and perhaps monday morning. The rest of the week (Monday-Tuesday-Wednesday) will be subcommittee meetings and joint meetings with other forums 06:16:37 From Amy Zwarico : Will the first scan be on Beijing or Amsterdam? 06:17:32 From Dhananjay Pavgi : Shouldn't it be on Amsterdam Maint rel 06:17:46 From Amy Zwarico : That's what I think as well 06:17:59 From Randa Maher (AT&T) : Since we already release, Amsterdam should be scanned to establish the baseline and make sure Beijing does not introduce new ones and try to close out in Beijing as capacity allows 06:18:43 From Amy Zwarico : Additionally, the project can run Coverity scans themselves as they are producing code. That way they can fix problems early. 06:20:49 From Brian : she isnt saying dont track beijing 06:21:33 From Amy Zwarico : how much Beijing code has been committed? 06:22:15 From Dhananjay Pavgi : Suggest start with Ams Maint rel. 06:22:42 From Dhananjay Pavgi : Then do Delta with Beijing and merge with Beijing? 06:26:19 From Catherine Lefevre : For NEXUS IQ, i think we need to find a way to report false positive. currently we can consult but not perform any update 06:30:13 From Gildas Lanilis - Huawei : why do we limit Nexus-IQ to PTLs? 06:30:22 From Gildas Lanilis - Huawei : why not to open to all? 06:32:48 From Don Levy : committer is a good solution -- i don't think we want to publically share the vulnerability info 06:39:54 From DENG Hui : I am on business trip? will catch up soon 06:40:02 From Kenny Paul : https://wikilf-onap.onapatlassian.orgnet/wiki/display/DW/Beijing+Release+Platform+Maturity 07:00:40 From Michael O'Brien : m.a.choquette@bell.ca