...
Jira No | Summary | Description | Status | Solution | |||||||
---|---|---|---|---|---|---|---|---|---|---|---|
Zoom security issues | Orange team is allowed to participate in the zoom meetings but not to lead them (it woud require installation of zoom client. | ||||||||||
Latest feedback received from Integration team | special thanks to Pawel W. who wrote most of the tests! Amy made w Wiki with Morgan shared following feedback: Some the part of docker tests need to be part of Jenkins jobs. It might be thta we will be responsible for the scripts and OOM team to get it into the place (intehrated into the Jenkins build). | Sylvain is acting PTL in OOM. For the only HTTP port exposed - action Amy – to contact PTL Bharath. - no OJSI ticket assigned as it should have appeared after our scans or component was not responding at the scanning moment. No value to open an additional tickets. MUSIC team should either: remove http, switch to https or ask for a waiver with justification. | |||||||||
Virtual ONAP event |
| We should come back to Architecture Subcommittee with a proposal for Service Mesh and once approved we should apprach TSC for a recommendation. | |||||||||
PTLs meeting update Proposal for upgrading vulnerable outdated packages in Guilin: -Guilin Package Updates – each project has its restricted access Wiki where ppt was uploaded with all recommended upgrades, importance of tracking progress, some new PTLs must have an access granted! (action on Kenny?) -SECCOM-265 – each project will have a jira ticket created with link to the Wiki – when is the deadline for Guilin requriements? | -JIRA report for PTLs regarding OJSIs outstanding SECCOM issues - shall emulator be whitelisted? Exceptional waiver to be granted. In long term all simulators must be fixed. If ports are not closed or moved to https, in Guilin release project will not get SECCOM waiver (as it can be granted only for 1 release!). PTLs meeting (held on April 13th) update: -CLI closed 3 http ports and one of the CVEs and running as root -A&AI should Close 15 issues -AAF – still one issue open -Optimization – 1 running as root – under fix - submitted -MUSIC – https port exposed – delivered -Code coverage – 5 exceptions not reaching 55% (all with waiver granted: AAF no resouces for side car, Policy engine will be excluded next release, OOF – no resources) -API documentation presentation by Andy Mayer | To approach David to check who would open Jira tickets per project for package upgrades. Communication of this policy should be done to ONAP community. | Security teast with Integration team | Amy will present relevant tests to next Integration team meeting on Wednesday. Proposed tests: Integration and Built Tests For Releases | To check with OOM team whether Integration or SECCOM should do adding new Jenkins jobs for CIS tests - it should be a part of OOM verify job - those tests should be ran if container changes or even all the time. | Service Mesh risk analysis – meeting summary available here | Service mesh requirements from security perspective followed by risk analysis. Review with Chaker | Jonathan finally resigned from PTL's position for AAF | John Franey is occupied with other activities and not only with AAF | ||
Scorecard for requirement req-223 | David proposed to descope this requirement. Progress is minor but SECCOM porposes to keep this requirement as in scope. | Tony - to update scoorecard with green status and comment on minor but positive direction. | |||||||||
OUR NEXT SECCOM MEETING CALL WILL BE HELD ON 28th OF APRIL'20 as on 21st we have vF2F meetings. |
...
View file | ||||
---|---|---|---|---|
|
View file | ||||
---|---|---|---|---|
|