Please find below the Minutes of Meetings and recording for the SECCOM meeting that was held on 5th of October 2021.
Jira No | Summary | Description | Status | Solution |
---|---|---|---|---|
TSC update |
| ongoing | ||
DCAE update |
| ongoing | mTLS to be further elaborated | |
Jakarta proposed dates | Global Requirements/Best Practice deadline for submission: 2nd of December by SECCOM:
| ongoing | ||
Last PTL meeting | Portal and VID dependencies (i.e., portal, portal-sdk & vid repos): Portal -> SDC UI (user authentication) -> Other projects are dependent on SDC (e.g., CLAMP GUI) VID to be removed , portal SDK as well. Projects unmaintained shall have their repos excluded from scans. EoL/EoS nomenclature could be used, open source communities do not maintain older versions, but encouraging to use latest greatest. | ongoing | ||
SCA automation efforts | We are xploring automation capabilities for moving data from Nexus-IQ to Wiki. | strated | ||
New Best practice for Jakarta release – new req to be open for Security logging | Set of questions prepared by Bob, to be addressed. Sidecar for logging - to be further decided by TSC who is going to maintain it. | ongoing | PTLs meeting to be used for collecting info on logging capabilities per project. | |
Feature intake template | Muddasar did not find prove of tracking the feature after its approval. | ongoing | To reach out PTLs on what could be the best way to tackle Jira template. Muddasar will propose some initial template, contributions are welcome. Muddasar will also reach out Alla as a follow up, feedback from testers might be also valuable. | |
OUR NEXT SECCOM MEETING CALL WILL BE HELD ON 12th OF OCTOBER'21. |
Recording:
SECCOM presentation:
ApplicationVisualization_2021_05_10.pptx