Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Jira No
SummaryDescriptionStatusSolution

ONAP 's evolution

Magnus's presentation invokes discussions in Archcom and in SECCOM.

SECCOM does not identify specific value in moving from subcommittee to Special Interest Group. We value fast decitsion making and execution on time.

ORAN defined ONAP core functions from their perspective. It cvould be a good baseline for us.

startedONAP security review questionnaire

In October the first application finished filling out our We went through first iteration of ONAP security review questionnaire, DCAE - ONAP Security Review Questionnaire Template

-3 x 1 hour sessions needed to go through the process.

-To be further discussed on how we should proceed with reviewing it.

Grade system usefullness to be discussed. Actions to follow up are valuable.

ongoingWe book the slot in the agenda for next week to collect feedback on Vijay's answers and questionnaire itself.

DL-Admin - name of DCAE repository.

General comment: answers are reasonable. 

Difficult to provide a grade, so we move the score filed into SECCOM Feedback/Recommendations as actionable item. 

Jiras to be created for every project to close issues in SonarCloud with description of what needs to be done - this could be part of the template as well.

ongoing

We are to provide feedback proposal in the questionnaire by next SECCOM -December 13th.

Tony to open a ticket to LF IT on license expiration for Toggle Cloack and Cloack plugins (used for an additional description under "+" mark. - done IT-24912 - SOLVED


Projects in OOM and HELM for removal

APPC, VID, Portal - decision needs to be taken to drop those projects from OOM.startedSlot to be booked at the incoming TSC meeting to get decision on removal.

Integration testsSECCOM Dashboard
  • Weekly scans re-enabled with Michal’s support:

-https://logs.onap.org/onap-integration/weekly/onap-weekly-dt-oom-kohn/2022-11/1828_1709-45/security/versions/versions.html30/

  • Daily scans:

https://logs.onap.org/onap-integration/daily/onap-daily-dt-oom-kohn/2022-12/06_03-37/




SCA - Automated NEXUS-IQ scans and recommendations for packages upgrades for London release 

Restricted Wiki ready to be consulted for PTLs for London release - thank you Amy!




TSC meeting (1st December)

-TSC Chair voting process completed – Pawel elected as new Chair

-ONAP consumers requested to provide their feedback




PTL meeting (5th December)

-ONAP Kohn release voted by TSC as ready to release




Portal PoC proposal by DT

The process I found on the Wiki: https://wiki.onap.org/display/DW/Project+Proposal+Process+Overview I see that Georg prepared the proposal inline with this process: https://wiki.onap.org/display/DW/PortalNG+Project+Proposal

PoC for NG Portal is approved by Archcom.


Byung and Chaker to provide clarification to Georg on Jira ticket as per ArchicomONES NA summary

Multiple interesting presentations, SECCOM included. It was great to meet some of you in person!

Waivers policy was presented and discussed. We can not accept never ending waivers.

TSC meeting

TSC Chair voting process started – Pawel candidates

Discussion on supercommitter rights

SCA analysisAutomated NEXUS-IQ scans and recommendations for packages upgrades for London release. Work in progress.

SECCOM MEETING CALL WILL BE HELD ON 13th OF
December'22, after next SECCOM is scheduled on January 10th 2023







Recordings: 

2022-12-06_SECCOM_week.mp4


SECCOM presentation:

2022-12-06 ONAP Security Meeting - AgendaAndMinutes.pptx