2023-05-23 Security Subcommittee Meeting Notes
Please find below the Minutes of Meetings and recording for the SECCOM meeting that was held on 23rd of May 2023.
Jira No | Summary | Description | Status | Solution |
---|---|---|---|---|
SPDX 3.0 update | Muddasar provided an update on SPDX version 3 and SBOM update. SLIDES Effort to move SPDX 3.0 to ISO standard still to be done. | |||
CPS Road to gold | Tony prepared his part of the deck for a common presentation and shared with Lee Angella. | ongoing | Tony will join next TSC and share SECCOM recommendation for 2FA. OJSI list of people to be reviewed. Amy will contact Jess. | |
DTF event and SECCOM presentation | Let's have a common SECCOM voice towards ONAP community. Slide with packages upgrades to be added as well as security template in architecture review template. | |||
Latest weekly scans | Marek was able to initiate latest run of scans. Results are progressing, cassandra and zk-tunnel-svc to be further elaborated. Marek does not know which project is using zk-tunnel-svc - it is not in Jenkins ONAP-discuss question was raised but still no feedback so far. | ongoing | ||
PTL meeting (May 22nd) | -PTLs upgrades for London release 2023-05-22 ONAP London release pakages upgrades.pptx - total vulns reduced significantly! -Issue raised for images creation (Sigul signing problem) – jira ticket opened by Liam last week: https://jira.linuxfoundation.org/plugins/servlet/desk/portal/2/IT-25552 -RC blocker! | |||
TSC meeting (May 18th) | -Review of the deck for Governance Board (presentation last week) -2FA issue presented as summary of meeting Andreas and LF- IT last week – still some actions pending… but -Feedback from Andy received ;-)
| |||
SECCOM MEETING CALL WILL BE HELD ON 30th May 2023. |
|
Recordings:
SECCOM presentation:
2023-05-23 ONAP Security Meeting - AgendaAndMinutes.pptx