...
Jira No | Summary | Description | Status | Solution | ||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Log PoC results presentation by Andrew (andrew.a.lamb@est.tec). Fluentbit sends logs to Elasticsearch and Kibana retrieves it from there. | done | About the requirement: [REQ-1072] SECURITY LOGS FIELDS – full PoC with CPS in Kohn and then GR candidate for London. | ||||||||||||||||||||||
LFN Developer & Testing Forum | Event June 13th-16th Porto, Portugal Please register: https://events.linuxfoundation.org/lfn-developer-testing-forum/ | started | ||||||||||||||||||||||
| started | Remaining topic proposals to be submitted. Brian to share what kind of security due diligence is performed by BellCanada. ONAP is used for 5G slicing orchestration. Fabian to check if could contribute on how qualify software to be deployed, what duediligence due diligence was performed. Follow-up with Kenny to be done. | OSA documentation update per release | Thomas asked for a branch to be created for Jakarta | started | Pawel to be done. | Last PTLs meeting – 25th of April |
1.SDC-3954 - open 2.SDNC-1692 - done 3.OOM-2957 – open – reassigned to Fiachra
1.OOM-2958 – open - reassigned to Fiachra 2.INT-2104 – in progress
1.SDC-4002 - open 2.SDNC-1703 - open 3.SO-3941 - open | Last PTLs meeting – 9th of May | Tony presented 5Y project review – CPS volunteered to be PoC and review questionaire. | ongoing | Once Toine completes, we will review the questionnaire. SECCOM to be updated. | Unmaintained Projects | Amy presented to ArchCom and to present to TSC 19 May. 12 May TSC call covered a release milestone. Good exchanges with Chaker, Byung:
Updated presentation is available below. | Amy to present at 19 May TSC call. Outline for the yellow to be added. | Update on failing security tests below: |
1.SDC-3954 - open 2.SDNC-1692 - done 3.OOM-2957 – open – reassigned to Fiachra
1.OOM-2958 – open - reassigned to Fiachra 2.INT-2104 – in progress
1.SDC-4002 - open 2.SDNC-1703 - open 3.SO-3941 - open | Security tests taht are performed to be reviewed for test coverage and identification of missing items. | SBOM: patch to add the path for VES | Adoption issue requires manual manipulation of workspace flag. Next step to get PTL onboard and set target date when LF IT would implement ONAP projects -5/17: no change in status with LFIT | ongoing | |||
CPS gold badge |
| ongoing | logging PoC report | Ajay (Ericsson) is working on the connection between FluntBit and ElasticSearch. He is leaving Ericsson end of this week, so some of our OOM team members have key learning sessions with him. I told Ajay to check in his code. We plan to report our log PoC progress/demo to SECCOM sometime soon. That is the plan. Prototype for logging fields. 5/17 Update:
| ongoing | update and demo will be provided - Byung coordinates that. | CPS PoC | Fabian tried to join Seshu. How to move forward: share results of the PoC during PTLs meeting to build awarness, followed by proposal to community. Closed loop for results is a defintely a value for the developer. | ongoing | Outcomes of CPS PoC to be presented in incoming weeks. | NIST 5G Cybersecurity draft document | https://csrc.nist.gov/publications/detail/sp/1800-33/draft | ongoing | Technical debt | started | We shall have Jira issues for all technical dept issues to track it. To review last 2 slides ta the next meeting - slides to be shared by Muddasar to SECCOM distribution list - doneSBOM | Jess to reach out LFN IT developer. | ongoing | ||||||
Notary v2 vs. Cosign | cathegories to be covered: software, documentation nad SBOM. Waiting for a feedback from Alex. | SECCOM requirement to be formed starting with software. | ||||||||||||||||||||||
Last TSC meeting | Positive feedback from TSC on unmaintained projects | |||||||||||||||||||||||
Technical debt | Last 2 slides reviewed again by Muddasar: What PTLs consider as technical debt? | started | Reviewing technical debt related Jira items in projects backlog. Muddasar to review backlogs per project. One slide to be prepared and then shared with PTLs and architecture subcommitee. | |||||||||||||||||||||
SECCOM MEETING CALL WILL BE HELD ON 24th 7th OF MAYJune'22. Review of technical debt slides with special focus on 2 last ones. |
Recording:
View file | ||||
---|---|---|---|---|
|
SECCOM presentation:
View file | ||
---|---|---|
|
|