2021-07-27 Security Subcommittee Meeting Notes
Please find below the Minutes of Meetings and recording for the SECCOM meeting that was held on 27th of July 2021.
Jira No | Summary | Description | Status | Solution |
---|---|---|---|---|
| Seccom criteria for the integration tests to pass a release |
| ongoing | To be presented at the TSC meeting |
| Last PTLs meeting |
| ongoing | Waiting for a list of project not participating in Istanbul release. |
| ESR Waiver | Currently 3 use cases are using ESR:
SO currently ESR in maintenance mode but can be obsolete. If nobody is using ESR, let's remove it from the Istanbul release. | ongoing | CCVPN to be check by Byung if they will use AAI. |
| Software BOMs, Hardware BOMs - Muddasar | Presentation: | ongoing |
|
| Dependency confusion attacks vs. ONAP SW build process | Packages are downloaded from Internet for ONAP. To be further elaborated with Bob and Samuli. | ongoing | E-mail to be sent to SECCOM distribution list/ONAP distribute. |
| Update from LFN | (IT-22333by Pawel, and IT-22334by Thierry)
| ongoing |
|
| Code quality and SonarCloud | Achievements to be presented to TSC | ongoing | Pawel to work with Fabian to present progress and achievements to TSC in this domain. |
| OUR NEXT SECCOM MEETING CALL WILL BE HELD ON 3rd OF AUGUST'21. | SBOM/HBOM continuation. |
|
|
Recording:
SECCOM presentation: