...
Jira No | Summary | Description | Status | Solution | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
LFN Developer & Testing ForumJune 13th-16th Porto, Portugal - summary |
| ongoing |
| ||||||||||||||
Waivers review between releases | Work started. Results for root_pods and unlimitted_pods from Guilin to Jakarta. | started | To be completed for remaining cathegories by Pawel - done | ||||||||||||||
ONAP Kohn recommended versions | Amy's team is doing last check for data quality. | ||||||||||||||||
Last TSC June 9th | sign-off – pushed to 23rd of June. Cassandra stability issue. SECCOM will not block the release. | ||||||||||||||||
Synch with OOM: |
| ongoing | |||||||||||||||
Python upgrades | DCAE removed Filebeat containers (they were running Python 2). | ONAP Kohn recommended versions | DTF presentation from Tata communication | Older ONAP version used. https://wiki.onaplfnetworking.org/display/DW/Database%2C+Java%2C+Python%2C+Docker%2C+Kubernetes%2C+and+Image+VersionsLFN Developer & Testing Forum Event June 13th-16th Porto, Portugal Please register: https://events.linuxfoundation.org/lfn-developer-testing-forum/ | started | started | 5G Superblueprint involvement | Security Interest Group for security as a code. Concept mandatory to support and optional to use. Let’s start with NIST document: https://csrc.nist.gov/publications/detail/sp/1800-33/draft | Muddasar to share template and keep SECCOM postedLN/2022-06-DD+-+ONAP%3A+The+Path+to+a+Production-Grade+ONAP | To be shared what we are doing with them. | |||||||
SBOM | Still no update from Jess. | Governance board to be escalated to for SBOM and LF IT proper focus. Ranny was contatced by e-mail as a follow-up of DTF discussion. | |||||||||||||||
Whitesource (mend.io) container scans | New ticket submitted to LFN IT: IT-24112 - Jess was asked for an update. | ||||||||||||||||
Technical debt | Muddasar reviewed jira tickets of DCAE and AAI. | Service Mesh | With Service Mesh AAF and MSB could be disabled. | Pawel to reach out Toine. | TSC update | Service mesh PoC – Andreas shared the status, HTTPs to be transfromed to either HTTP or gRPC within the container, proxy takes care of secure communication. Jakarta sign-off pushed to 9th of June, M2 date still to be confirmed by TSC. | Conditional check for HTTP and Service Mesh | Pawel to check with Michal. | SBOM | Jess to reach out LFN IT developer later this week. SBOM is the fundamental gear. Ranny is already in the loop. We need to advocate on SBOM | ongoing | Escalation with LFN Governing Board? Ranny to be contacted? Cost to be retrieved from Jess by Muddasar. | Logging PoC | https://gerrit.nordix.org/c/onap/oom/+/13370PTLs to be consulted. to know how PTL thinks when looking at Jira tickets. Vijay will be on PTO for next 2 weeks, so it will not be DCAE, AAI under consideration. | Ask at the next PTLs meeting for volunteering PTLs. Amy and Muddasar to synch each other on that. | ||
Automation for dependency management | https://github.blog/2020-06-01-keep-all-your-packages-up-to-date-with-dependabot/ | ||||||||||||||||
Muddasar is presenting at HardenStance (6/23) MITRE's FiGHT framework for 5G security. | In case anyone is interested here is the link: https://events.adaptivemobile.com/hardenstance-ttsi2022/agenda-day2 | ||||||||||||||||
SECCOM MEETING CALL WILL BE HELD ON 28th OF June'22. |
...
View file | ||||
---|---|---|---|---|
|
SECCOM presentation:
View file | ||||
---|---|---|---|---|
|