M1 Release Planning Milestone
Practice Area | Checkpoint | Yes/No | Evidence - Comment | How to? |
Security | Has the Release Security/Vulnerability table been filled out in the protected Security Vulnerabilities wiki space? |
| Table in in the protected Security Vulnerabilities wiki space corresponds to the latest NexusIQ scan | PTL reviews the NexusIQ scans for their project repos and fills out the vulnerability review table |
Have known vulnerabilities (critical and severe) to address/remove in the release been identified with jira tickets? |
| Jira tickets exist for vulnerabilities or the project indicates that there will be no vulnerable library replacement | Complete Jira tickets | |
Propose that previous line replace this question in the current M3 template: Do you have a plan to address by M4 the Critical and High vulnerabilities in the third party libraries used within your project? |
|
| Ensure by M4 the Nexus-IQ report from “Jenkins CLM” shows 0 critical security and severe vulnerabilities. Open the Nexus-IQ report for the details on each repo. | |
Has the project committed to the release CII badging level |
| completion of the ONAP level CII questions | ||
If the project uses java, has the project integrated with the oparent.pom? |
| Oparent.pom included in project |
|
M2 Release Planning Milestone
...
M3 Release Planning Milestone
Practice Area | Checkpoint | Yes/No | Evidence - Comment | How to? |
Security | Has the Release Security/Vulnerability table been updated in the protected Security Vulnerabilities wiki space? |
| Table in in the protected Security Vulnerabilities wiki space corresponds to the latest NexusIQ scan | PTL reviews the NexusIQ scans for their project repos and fills out the vulnerability review table |
Has the project committed to enabling transport level encryption on all interfaces? |
| Requirements and test cases for transport layer encryption have been created for all interfaces not currently supporting encryption. |
| |
Has the project documented all open port information? |
|
|
| |
Has the project provided the communication policy to OOM and Integration? Gildas recommends this be moved to M1 |
|
|
| |
| Do you have a plan to address by M4 the Critical and High vulnerabilities in the third party libraries used within your project? Currently also in M1 table |
|
| Ensure by M4 the Nexus-IQ report from “Jenkins CLM” shows 0 critical security vulnerability. Open the Nexus-IQ report for the details on each repo. |
M4 Release Planning Milestone