...
Practice Area | Checkpoint | Yes/No | Evidence - Comment | How to? |
---|---|---|---|---|
Product Management | Are all provisional APIs interface (stub) been defined (at beta-quality level)? | N/A | OOM Provides no APIs | |
Is there a final list of externally consumable APIs available? | N/A | OOM Provides no APIs | ||
For all completed Sprints, have Sprint Backlog Stories been marked as "Closed" in Jira? | Yes | Difference between a Product and Sprint Backlog | ||
Are all tasks associated with the completed Sprint Backlog Stories been marked as "Closed" in Jira? | Yes | |||
If applicable to your project, has your team been able to clear the project' blockers? If not provide status on the plan to close the blocker(s). | Link to blockers. | |||
What new features or changes to existing features in this project scope need to be communicated to VNF Providers? List the changes in the Evidence tab. | None | |||
If yes to the previous question, have these been communicated to the VNF Requirements project? | N/A | |||
Release Management | Have all source code files been updated with License Apache 2 header? | Specific rules and instruction are available in ONAP wiki. | ||
Has the year format in copyright header of all source code files been updated? (Rules for new files created in 2018 and existing files modified in 2018 are different) | During ongoing development of Dublin features, all new and modified files will include current year 2019. | Guidance on year format | ||
In case source code can't be edited, has a "License.txt" file been placed at the root directory for which the license is applicable? | Yes | OOM Global License File | Guidance for source code file that can't be edited | |
(a) Has the Project Team added appropriate license and copyright notices to all ONAP source code and documentation files, where possible for the particular file format? | Yes | |||
(b) Has the Project Team reviewed and understood the most recent license scan reports from the LF, for both (a) licenses within the codebase and (b) licenses for third-party build time dependencies? | Yes | No violations see report | ||
For both (a) and (b) questions, have all high priority non-Project Licenses been either removed, planned for removal before code freeze, or escalated as likely exception requests? | N/A | |||
Have all API projects dependencies been captured? | N/A | OOM provides no APIs. | The source of information for the API dependency is the "API Incoming Dependency" of the M1 Release Planning deliverable. Please update the source accordingly, and let The Release Manager aware of the changes. | |
Development | For new projects approved for this release, have all defined repositories source code been placed into Gerrit? | Yes | TODO: Provide link to evidence offline-installer | For evidences, provide link(s) to Gerrit repos by providing the URL as shown in this example |
Has the project team reach the Automated Unit Test Code Coverage expectation? (Refer to artifacts available in Sonar) | N/A | Helm/Kubernetes do not have unit tests and is not supported by Sonar. See Sonar OOM Results | ||
Is there any binaries (jar, war, tar, gz, gzip, zip files) in Gerrit project repository? | No | Refer to CI Development Best Practices | ||
Could you ensure that all proprietary trademarks, logos, product names, company name, etc. have been removed? All ONAP deliverables must comply with this rule and be agnostic of any proprietary symbols. | Yes | |||
Is there any pending commit request older than 36 business hours in Gerrit? | Yes | Working to address. | ||
Have all the Jenkins jobs successfully passed (Merge-Jobs)? | Yes | OOM CD Jenkins Jobs | ||
Are all snapshot binaries available in Nexus? | No | https://nexus.onap.org/content/sites/oom-helm-staging/ TODO: raise risk item to indicate LF helm chart snapshot job is not implemented for Dublin | ||
Integration and Testing | Have functional test cases i.e. CSIT been documented in wiki? It should include at least 1 or 2 CSIT that will be run on Lab-xxx-OOM-Daily Jenkins Job | Provide link to evidence | ||
Have you implemented in Jenkins at least 1 functional test case for each of the project repository? | As an evidence, provide a link to Jenkins (CSIT Jobs) that shows a sample test case implemented (1 job for each repo). | As an example (provided by Integration Team) | ||
Has the project code successfully passed the Build process? | Goal is to ensure your project latest commits have not broken the build. | |||
Documentation | Has the team identified and outlined the set of documentations to be delivered in this Release? | |||
Security | Has the Release Security/Vulnerability table been updated in the protected Security Vulnerabilities wiki space? | Table in in the protected Security Vulnerabilities wiki space corresponding to the latest NexusIQ scan | PTL reviews the NexusIQ scans for their project repos and fills out the vulnerability review table | |
Have all project containers been designed to run as a non-root user? | https://wiki.onap.org/display/DW/Best+Practices
|
...