2023-04-18 Security Subcommittee Meeting Notes

Please find below the Minutes of Meetings and recording for the SECCOM meeting that was held on 18th of April 2023.

Jira No

Summary

Description

Status

Solution

Jira No

Summary

Description

Status

Solution



Security Questionnaire for CPS

SECCOM reviewed final updates and completed review with positive results.

We will look for next candidate.

done

Final review is positive and will be provided by Pawel to CPS today!

Pawel to share with PTLs that we are looking for a next project.



5G suplerblueprint

Muddasar will provide presentation







LFX Security Dashboard

Need to get link from Jess.



To be discussed at the next SECCOM.



SBOM global implementation in ONAP

Ticket was opened by Muddasar to LF IT - Signed SBOM implementation for all ONAP project at Global level (IT-25341)

TSC conditionally approved

PTL no objections

Jess confirmed turning on at the global JJB config.

Muddasar is doing follow up – check at the release date







Wrapping up the unmaintained repo task force

link

We wait till M4 for TSC presentation



Final list of unmaintained to be prepared for next SECCOM and M4 milestone (April 27th). 



PTL meeting (April 17th)

Matt will help us with CI pipeline review







TSC meeting (April 13th)

Network Slicing Use Case update – we are looking for contributors

New ONAP mission statement discussion – moved to MAC for their advise

SECCOM CI/CD Security

June D&TF is the second week of June 6th -9th – virtual event only







Security test cases review 

Matt was contacted by Muddasar. Started exchanges on Ci/CD pipeline security.







SECCOM MEETING CALL WILL BE HELD ON 25th April 2023. 

Final list of unmaintained and packages upgrades for London release.

Automation, orchestration and security presentation at ONE by Muddasar.













Recordings: 

2023-04-18_SECCOM_week.mp4

SECCOM presentation:

2023-04-18 ONAP Security Meeting - AgendaAndMinutes.pptx