We will start our meetings by mentioning the project's Antitrust Policy, which you can find linked from the LF and project websites. The policy is important where multiple companies, including potential industry competitors, are participating in meetings. Please review and if you have any questions, please contact your company legal counsel. Members of the LF may contact Andrew Updegrove at the firm Gesmer Updegrove LLP, which provides legal counsel to the LF.
#AGREED the TSC approves remediating log4j as the top priority for the ONAP community requiring immediate action to correct in both Istanbul and master branches.
Krzysztof Opasiak will file a CVE on ONAP's behalf (as soon as the list of projects are all confirmed at a minimum
SECCOM to present the action plan to the next PTL call on 12/20
SECCOM will create the JIRA tickets for the impacted projects in order to solve it as part of the Istanbul maintenance release and the Jakarta release. They will track to completion, supported by our release manager, David McBride and the Integration Team (through the Docker Scan)
#AGREED The log4j vulnerability will mandate an Istanbul maintenance release. The maintenance release should be limited to log4j remediation only.
cl664y@att.com - no changes to Jakarta release schedule due to focus on log4j issue for now. Continue to monitor progress on the issue and re-evaluate as we approach M2 in January.