ONAP Security Maturity Metrics
SECCOM will define a set of metrics per release that will be used to measure the security maturity of each ONAP project. Each project will have it's maturity level documented in the release notes.
Guilin - DRAFT
All OJSI tickets closed.
All mariadb-galera and yyyy passwords removed from Helm charts.
All external HTTP ports converted to HTTPS.
Java and Python projects are all using the recommended versions.
All projects that use Python have upgraded to Python 3 (version 3.8.0).
All projects that use Java have upgraded to Java 11.
Exceptions to Java 11 and Python 3 Migration at End of Frankfurt Release
All direct dependencies containing Critical or Severe vulnerabilities are updated per SECCOM recommendations.
Generate logs that can be collected by Kubernetes.
Frankfurt
All OJSI tickets closed, with the following exception.
All fixes that have an unresolved dependency on AAF integration.
Open OJSI tickets: OJSI Tickets Status
All mariabd-galera passwords removed from Helm charts, where the chart is using the common mariadb-galera chart. This applies to both common and dedicated instances of the db.
All external HTTP ports converted to HTTPS, with the following exceptions.
HTTP ports discovered after M2/M3
All fixes that have an unresolved dependency on AAF integration
HTTP ports on testers