...
Jira No | Summary | Description | Status | Solution | ||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
done | About the requirement: [REQ-1072] SECURITY LOGS FIELDS – full PoC with CPS in Kohn and then GR candidate for London.Synch with OOM | Security dashboard at 60%: https://logs.onap.org/onap-integration/daily/onap-daily-dt-oom-master/2022-06/07_07-48/ and Versions reporting at 57%: https://logs.onap.org/onap-integration/weekly/onap_weekly_pod4_master/2022-05/20_21-56/ latest run by Michal for the weekend | ongoing | |||||||||||||
Python upgrades | DCAE removed Filebeat containers (they were running Python 2). | |||||||||||||||
ONAP Kohn recommended versions | ||||||||||||||||
LFN Developer & Testing Forum | Event June 13th-16th Porto, Portugal Please register: https://events.linuxfoundation.org/lfn-developer-testing-forum/ | started | ||||||||||||||
| started | Remaining topic proposals to be submitted. Brian to share what kind of security due diligence is performed by BellCanada. ONAP is used for 5G slicing orchestration. Fabian to check if could contribute on how qualify software to be deployed, what due diligence was performed. Follow-up with Kenny to be done. | SBOM | Jess to reach out LFN IT developer. | ongoing | Notary v2 vs. Cosign | cathegories to be covered: software, documentation nad SBOM. Waiting for a feedback from Alex. | SECCOM requirement to be formed starting with software. | Last TSC meeting | Positive feedback from TSC on unmaintained projects | Technical debt | started | Reviewing technical debt related Jira items in projects backlog. Muddasar to review backlogs per project. One slide to be prepared and then shared with PTLs and architecture subcommitee. | |||
5G Superblueprint involvement | Security Interest Group for security as a code. Concept mandatory to support and optional to use. Let’s start with NIST document: https://csrc.nist.gov/publications/detail/sp/1800-33/draft | Muddasar to share template and keep SECCOM posted. | ||||||||||||||
Whitesource (mend.io) container scans | New ticket submitted to LFN IT: IT-24112 | |||||||||||||||
Technical debt | Muddasar reviewed jira tickets of DCAE and AAI. | |||||||||||||||
Service Mesh | With Service Mesh AAF and MSB could be disabled. | Pawel to reach out Toine. | ||||||||||||||
TSC update | Service mesh PoC – Andreas shared the status, HTTPs to be transfromed to either HTTP or gRPC within the container, proxy takes care of secure communication. Jakarta sign-off pushed to 9th of June, M2 date still to be confirmed by TSC. | |||||||||||||||
Conditional check for HTTP and Service Mesh | Pawel to check with Michal. | |||||||||||||||
SBOM | Jess to reach out LFN IT developer later this week. SBOM is the fundamental gear. Ranny is already in the loop. We need to advocate on SBOM | ongoing | Escalation with LFN Governing Board? Ranny to be contacted? Cost to be retrieved from Jess by Muddasar. | |||||||||||||
Logging PoC | ||||||||||||||||
SECCOM MEETING CALL WILL BE HELD ON 21st OF June'22. |
...
View file | ||||
---|---|---|---|---|
|
SECCOM presentation:
View file | ||||
---|---|---|---|---|
|