Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Jira No
SummaryDescriptionStatusSolution

ONAP enterprise business workgroup OPS 5G updateogoingSlide deck for new Global Requirements

For CII Badging ongoing conversation for mainained/unmaintained projects at passing level.

Infrastructure related question (hardening of the site) for gold level - all our projects set unmet - LF would have to handle.

Private vulnerability reports.

Cultural change - possibility to add new people to project.

Statement coverage at 90% and test branch coverage at 80%.

Couple of questions that are project level that should be met - example 2 people's review.

We are actively involved with David Wheeler to simplify CII badging answers by automationGlobal view on LFN projects landscape and 5G E2E implementation:

Image Added

-CNF Task Force/ORAN enterprise workgroup meeting on 31st of March,

-5G OPS – Open Programmable Software, as much of open source as possible

-All work within community unclassified

-Magma – orchestrator – could be orchestrated by ONAP SO.

-4 uses cases: enhanced mobile broadband, multimachine type communication, ultra low latency, voice over new radio

Image Added

Image Added

Open source to be part of commercial solutions.

ongoingNext meeting is scheduled for April 14th.

Slide deck for new Global Requirements

No slot at the last TSC, although booked.

For CII Badging requirement is that the projects will exhibit continous improvements towards achieving and maintaining CII Badging Gold - that is an aspirational goal.

ongoing

To be presented at the incoming TSC meeting - slot in the next agenda to be booked..

LoE = Level of Effort for packages upgrades to be collected from projects which succeeded in their efforts.

Tony to be added to private vulnerability reports.

To further discuss within SECCOM Tony's findings.


Training for SonarCloudScoping meeting on Thursday at 5:30 CEST.Training for SonarCloud

Meeting last Thursday done. Questions collection to be addressed by training:

  • take a look at how we are using SonarCloud to benefit from it even more
  • how to automatically eliminate unmaintained projects
  • how to ensure that PTLs have right authority to be able to use SonarCloud capabilities and be able to do the lifecycle, it does support, example: marking false positive, right now we can only change the code to not reappear anymore 
ongoing

Last PTL meeting

Discussion on change coming from project after the deadline on RC0/RC1 milestone.

Last TSC meeting

Presentation about ONAP & O-RAN, usage of MVP of ONAP.

ongoing

Slot to be booked for the next TSC meeting for moving best practices to global requirements

Certificates issues (expiring)Raised by Turkish company (Urlak?) that works with ONAP for 3 years already in 5G context.ongoingOOM team to be contacted - they meet on Wednesdays.

Global Requirements on the project level: 2 Factor Authentication, Site Hardening, code review standard, copyright profile at every source file. Some CII Badging questions have answers ONAP wide.

ongoingInfrastructure changes at the LF level will need some more time

LF InternshipsDeadline soon... Bus factor requirment could be a good use case.ongoing

Logging management follow-up

To be checked the status whther Stdout usage for logging was voted as Best Practice.

Fabian created 3 tickets to SDC. FluentD to be used to export logs.

ongoingTo be check the status with David McBride.Voting process for LFN Board candidates

PLease use your voting rights to support our Colleagues - e-mail from Casey:

Amy, Krzysztof and Martial.

ongoingComments for logsIn 2 weeks to review Fabian's comments.ongoingAutomating in CII BadgingContributions are welcome - please contact Tony. Python skills would be needed or any equivalent.ongoing

In Honolulu it was PoC and not best practice.

Feedback from David: https://lf-onap.atlassian.net/wiki/x/zRv7, action: first step is to review and socialize with the PTLs, good to request time in the weekly PTL meeting for this.  Next, need to propose it as a best practice for the Istanbul release, which will require approval by the TSC before M1.

ongoingTo book a slot for next PTLs meeting.

CII Badging – automationSupport for Tony, volunteers are welcome


NEXUS-IQ scans analysis

We wait with the SCA analysis untill code is stable, post RC1?

on standby


OUR NEXT SECCOM MEETING CALL WILL BE HELD ON 13th OF APRIL'21. 





Recording:

View file
name2021-04-06_SECCOM_week.mp4
height150


SECCOM presentation:

View file
name2021-04-06 ONAP Security Meeting - AgendaAndMinutes.pptx
height150