...
Jira No | Summary | Description | Status | Solution | Review of the deck prepared by Muddasar | "Building a better 5G future..." for OSS associated conference (May 9th). | started | SBOM Types & Minimum Requirements for VEX Documents - shared by Muddasar | Improvements in SBOMs and sharing info on vulnerabilities. The Types of SBOM document summarizes common types of SBOMs that tools may create in the industry today, along with the data typically presented for each type of SBOM. As software goes from planning to source to build to deployed and used, tools may be able to detect subtle differences in the underlying components. These types will allow for better differentiation of tools and in the broader marketplace. The Minimum Requirements for VEX document specifies the minimum elements to create a VEX document. This will allow interoperability between different implementations and data formats of VEX. It will also help promote integration of VEX into novel and existing security tools. This document also specifies some optional VEX elements. Today ONAP supports pull method for SBOM. | ||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
startedCPS Road to gold | Idea of submitting presentation proposal for DTF virtual event on CPS road to gold with Tony’s contribution (few additional slides on why CPS could not get to gold and what are the missing pieces in the infrastructure). Main blocker: lack of second verification - 2FA is missing at the LF IT infra. First priority to get it supported for committers (MFA at the gerrit level), other group with lower priority are code submitters (MFA at the git level). | started | 2FA is missing at the LF IT infra – Amy to share with TAC. To be checked if gerrit supports MFA. Tony could present this issue to TSC (next week?) Pawel to share with Lee Anjella the proposal for a joint presentation. | ||||||||||||
Building a better 5G future... | Muddasar is presenting today at the ONE conference in Vancouver - crossing fingers! | ||||||||||||||
LFX Security Dashboard https://security.lfx.linuxfoundation.org/ ongoing
| CPS presentation for DTF virtual event | Tony is open to help and contribute. | TSC meeting (April 20th) | Amy will meet with Jess later today. | Final list of unmaintained and packages upgrades for London release | We wait till M4 for TSC presentation. | ongoing | Fix to be provided for packages upgrades. | PTL meeting (April 24th) | Liam will provide his feedback on Policy interest to participate in Security Questionnaire for next project | ongoing | ONAP Takeaways summaryhad a meeting with Jess. -LFX is a security framework - open for different pipelines, no dictated tools, and absolutely no integration with LF purchased/licensed products: Nexus-iq or Sonarcloud. -VEX and SBOM under exchanges | ongoing | Value to ONAP projects could be increased by providing configuration templates for existing tools. | |
Latest weekly scans | Marek was able to initiate latest run of scans. Results are progressing, cassandra and zk-tunnel-svc to be further elaborated. | Pawel to check with Marek if he recalls zk-tunnel-svc is part of which project. | |||||||||||||
PTL meeting (May 8th) | Liam confirmed interest in questionnaire review Discussion on Java 17 recommendation impact and dependency with other upgrades (Spring 6 and Springboot 3). Database, Java, Python, Docker, Kubernetes, and Image Versions | Tony to be contacted by Policy team member for 5 Year security review. | |||||||||||||
TSC meeting (May 4th) | Final list of unmaintained by Amy presented to TSC. If there is no PTL, tickets shall be assigned to Pawel as TSC Chair who could reassigned further. | ||||||||||||||
SECCOM Montreal requirements | Existing Global requirements -Epic REQ-437: COMPLETION OF PYTHON LANGUAGE UPDATE (v2.7 → v3.8)
-Epic REQ-438: COMPLETION OF JAVA LANGUAGE UPDATE (v8 → v11)
-Epic REQ-439: CONTINUATION OF PACKAGES UPGRADES IN DIRECT DEPENDENCIES
-Epic REQ-443: CONTINUATION OF CII BADGING SCORE IMPROVEMENTS FOR SILVER LEVEL
-Logging for Java
| Bob to share Jira as a reference. JIRA ticket for the security logging for Java containers. | |||||||||||||
Integration in Subcommittees | Requirements Subcommittee will be integrated under Architecture Subcommittee. | ||||||||||||||
SECCOM MEETING CALL WILL BE HELD ON 16th May 2023. | SBOM Types & Minimum Requirements for VEX Documents |
Recordings:
SECCOM presentation:
2023-05-09 ONAP Security Meeting - AgendaAndMinutes.pptx