...
Jira No | Summary | Description | Status | Solution |
---|---|---|---|---|
Synch with ONAP documentation - Thomas | Release Notes organization: Log4j vulnerabilities in direct dependencies were removed from A&AI, DMAAP, SDNC and VNFSDK. Log4j vulnerabilities introduced by transitive dependencies are still in A&AI, CCSDK, DCAE, DMAAP, MULTICLOUD, SDNC, SO, VNFSDK. https://docs.onap.org/en/latest/release/index.html#istanbul-maintenance-release-9-0-1
Projects/functional repos with transitive dependencies for log4j:
| ongoing | Tickets to be open by Pawel for remaining transitive dependencies on per relevant project basis: | |
Security Logging Presentation to Akraino TSC - Bob | Logging today at 1500 UTC. Here is the meeting info if you would like to join. https://wiki.akraino.org/display/AK/TSC+2022-03-08+%28Tuesday%29+7%3A00+am+Pacific | ongoing | ||
ONAP Security Review Questionnaire template first cut – Tony | https://wiki.onap.org/display/DW/ONAP+Security+Reviews We want to start simple and small. Time it takes to document vulnerabilities and time it takes to resolve it. Assurance section might be expanded. | ongoing | SECCOM members to review proposed draft and further discuss next week. | |
Packages upgrades for Jakarta | As of today the project teams have upgraded 103 of 299 identified vulnerable direct dependencies for the release (~34%). | Ask TSC to have focus on security by sending an e-mail to TSC and discuss this issue on Thursday. | ||
Time shift in US on 13th March and in EU on 27th March. | Please check if the meeting invitations are displayed accordingly. | |||
Quality gates | No update. Meeting with Seshu to be done. | |||
Issue with Wiki creation by Tony | Ticket to be created to solve the issue | Ticket to be created to solve the issue | ||
SECCOM MEETING CALL WILL BE HELD ON 22nd OF MARCH'22. | Quality gates for code quality improvements - continuation of the discussion. 5Y review criteria. |
Recording:
View file | ||||
---|---|---|---|---|
|
SECCOM presentation: