...
Practice Area | Checkpoint | Yes/No | Evidences | How to? |
---|---|---|---|---|
Security | Has the Release Security/Vulnerability table been updated in the protected Security Vulnerabilities wiki space? | Table in in the protected Security Vulnerabilities wiki space corresponds to the latest NexusIQ scan | PTL reviews the NexusIQ scans for their project repos and fills out the vulnerability review table | |
Has the project committed to enabling transport level encryption on all interfaces and the option to turn it off? | Requirements and test cases for transport layer encryption have been created for all interfaces not currently supporting encryption. | |||
Has the project documented all open port information? | ||||
Has the project provided the communication policy to OOM and Integration? | Recommended Protocols | |||
Do you have a plan to address by M4 the Critical and High vulnerabilities in the third party libraries used within your project? |
| |||
Architecture | Has the Project team reviewed the APIs with the Architecture Committee (ARC)? | Architecture walkthrough to understand how each project contributes on Release Use Case. ARC to organize the walkthrough. | ||
Is there a plan to address the findings the API review? | Link to plan | The plan could be as simple as a Jira issue to track the implementation of findings or a documented plan within the wiki. | ||
Does the team clearly understand that no changes in the API definition is allowed without formal TSC review and approval? | NA | In the case some changes are necessary, bring the request to the TSC for review and approval. | ||
Is there any changes in the scope, functionalities, deliverable, dependency, resources, API, repositories since M1 milestone? | If Yes, please a link to the evidence of these changes. | Critical point to understand is that change is inevitable, and that right timing and clear communication to the community will ease the process of accepting changes. | ||
Provide link to the API Documentation. | ||||
Release Management | Are committed Sprint Backlog Stories been marked as "Closed" in Jira board? | Provide Link to Project backlog | ||
Are all tasks associated with Sprint Backlog Stories been marked as "Closed" in Jira? | ||||
Have all findings from previous milestones been addressed? | Provide link to JIRA findings | |||
Development | Is there any pending commit request older than 36 Business hours in Gerrit? | |||
Has the project team reach the Automated Unit Test Code Coverage expectation? (Refer to artifacts available in Sonar) | Goal: 55% for Incubation project in the current release | Guidance on Code Coverage and Static Code Analysis Tools: Sonar | ||
Do you have a plan to address by M4 the Critical and High vulnerabilities in the third party libraries used within your project? | Ensure by M4 the Nexus-IQ report from “Jenkins CLM” shows 0 critical security vulnerability. Open the Nexus-IQ report for the details on each repo. | |||
Are all the Jenkins jobs successfully passed ( Merge-Jobs)? | Provide link to evidence | |||
Are all binaries available in Nexus? | Provide link to evidence | |||
Integration and Testing | Have 50% of System Integration Testing Use Cases been implemented successfully in Jenkins? | Provide link to evidence | ||
Has the project code successfully passed the Daily Build process? | Goal is to ensure the latest project commit has not broken the Integration Daily Build | |||
Has the project code successfully passed the daily Integration sanity test (in another words, no blocking issue reported on the project)?Goal is to ensure the latest project commit has not broken the Integration Daily Build | Check blocking issue page |