Please find below the Minutes of Meetings and recording for the SECCOM meeting that was held on 25th of October 2022.

Jira No
SummaryDescriptionStatusSolution

TSC electionsupcoming TSC Chair/Vice Chair elections


Unmaintained meeting update

-Connecting images to repos is nested within the JJBs

-Options: (1) use tagging to connect images to repos, (2) POM files have container names, (3) multi-image repos have info in JJB, (4) use logs of jenkins build jobs

-Repo Tagging: https://help.sonatype.com/repomanager3/nexus-repository-administration/tagging

Jessica will attend the 31 October Unmaintained Repo meeting

ongoing

Tony Hansen proposed an automated solution using POM and JJBs to associated images to repos


SBOM updatePTLs or LF IT to be responsible for configuration change (JJB template). If no PTL, the change shall be on LF IT.

Where SBOMs are not produced, troubleshooting needs to be done by LF IT and SECCOM.

Jiras per projects to be issued by Muddasar. IF PTL exists, it would be assigned to him/her, otherwise to LF IT (Jess?).


Logging requirement - Bob and Byung

-Python PoC, PTL to be targeted, internal resource available, library to be prepared

-Update on presentation to PTLs

-Recommendation from Vijay – work with Integration team

-GR for Java – pushback from PTLs

-Decision: proceed with java GR for London


Agreement for PoC to be achieved with Vijay.

Security asessment questionnaire – ongoing Tony with Vijay

-DCAE - ONAP Security Review Questionnaire Template

-SECCOM next steps: define a scoring methodology


Add to Nov 1 SECCOM agenda as first item: discuss scoring methodology

LFN Developer & Testing Forum NA
  • Registration Open
  • Nov. 17 & 18 2022 Seattle, WA, USA, In Person
  • Proposed submissions
    • [Plenary/ONAP] Productization of Assured Opensource Software
    • [Day 1 – Plenary] SBOM implementation and challenges in ONAP
    • [Day 2 – ONAP] London security requirements, ONAP architecture update, ONAP ServiceMesh



Daylight saving time To be further elaborated. In US in the week of November 4th, last weekend of October for Europe/Poland.


SECCOM MEETING CALL WILL BE HELD ON 1st OF November'22. 







Recordings: 

audio1133433072.m4a

video1133433072.mp4


SECCOM presentation:

2022-10-25 ONAP Security Meeting - AgendaAndMinutes.pptx

London SECCOM Requirements - revised.pptx