Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Risk IDProject Team or person identifying the riskIdentification DateRisk (Description and potential impact)Team or component impacted by the risk

Mitigation Plan

(Action to prevent the risk to materialize)


Contingency Plan - Response Plan

(Action in case of the risk materialized)

Probability of occurrence (probability of the risk materialized)

High/Medium/Low

Impact

High/Medium/Low

Status
1OOF

 

Problem with removing GPLv3 components from OSDF docker imageOSDFPossible ways of solving the problem are documented here. OSDF Image optimizationRaise an exception for this release and continue to work on itMediumMediumIdentified
2Policy

 

Problems resulting from upgrade of jetty-serverPolicy, oparentRequest update to oparent sooner rather than later so that impact may be assessedRaise an exception for this release and continue to work on itLowHighIdentified
3Policy

 

Problems resulting from upgrade of CDS jarsPolicy, CDSBe proactive with CDS team
MediumLowIdentified
4Policy

 

TSOCA Control Loops are dependent on migration of DCAE kubernetesPolicy, DCAEBe proactive with DCAE team
MediumMediumIdentifier
5AAI

 

Lack of resources to deliver 

REQ-439 - CONTINUATION OF PACKAGES UPGRADES IN DIRECT DEPENDENCIES 

AAIMake best efforts to resolve the security findingsRaise an exception for this release and continue to work on itMediumLowIdentified
6AAI

 

Janusgraph does not support Java 11

REQ-438 - COMPLETION OF JAVA LANGUAGE UPDATE (v8 → v11)

AAINot much we can doRaise an exception for this release and hope janusgraph supports java 11 in the coming releaseHighLowIdentified
7DMaaP Message Router

 

REQ-438 - COMPLETION OF JAVA LANGUAGE UPDATE (v8 → v11)  

Confluent base images used by Message Router kafka/zookeeper are built using Java 8. Move to a newer version is a risk based on resources/time constraints.

DMaaPSource some more resources for the project to address this issue.Obtain a waiver for the problem packagesHighLowIdentified
8DMaaP kafka

 

Code coverage for the dmaap-kafka project failed to meet the required goal.

DMaaP kafkaCode coverage goalsObtain a waiver for the impacted componentsHighLowWorking with Sonar community to fix this unexpected coverage drop.
9CCSDK

 

Most recent AAF shiro plugin version appears to still be compiled for Java 8, which causes problems when installed in Karaf under Java 11.AAFAAF plugin is not installed until this is resolved - installing it breaks the container.Will continue to use built-in ODL credentials instead of using AAF to authenticateHighLowIdentified
10DCAE

 

REQ-438 - COMPLETION OF JAVA LANGUAGE UPDATE (v8 → v11)

dcaemod-designtool & dcaemod-nifi-registry has dependency on upstream (NiFI) project which is currently on java8


DCAEContinue H versionWaiver/Exception to  be filed with SECCOM HighLowIdentified
  11DCAE

 

Scope of DCAE Transformation (REQ-685) being large and dependency on multiple projects (DCAE, OOM, Integration, CLAMP) - there is risk in completing the planned scope in entierity for this releaseDCAE, Integration, OOM, CLAMPPeriodic assessment with all impacted project;  adjust target scope if required.Defer subset of features to J releaseMediumMediumIdentified
12UUI

 

Jira
serverONAP Jira
serverId425b2b0a-557c-3c0c-b515-579789cceedb
keyUSECASEUI-574

Update the vulnerable direct dependencies in code base but the result is unknown, and we don't have the lab environment to verify it now

UUIDelay it until our lab environment is ready
HighLowIdentified
13UUI

 

Jira
serverONAP Jira
serverId425b2b0a-557c-3c0c-b515-579789cceedb
keyUSECASEUI-405

Not enough human resource to do this modification

UUIContinue working on it until next release
HighLowIdentified
14SDC

 

Not able to fix all the identified security issues required by the global requirement 

Jira
serverONAP Jira
serverId425b2b0a-557c-3c0c-b515-579789cceedb
keyREQ-443
, reported in 
Jira
serverONAP Jira
serverId425b2b0a-557c-3c0c-b515-579789cceedb
keySDC-3607
 and 
Jira
serverONAP Jira
serverId425b2b0a-557c-3c0c-b515-579789cceedb
keySDC-3608

SDCSource resources to take a look and responsibility to fix the issues as soon as possible. Items will be tracked twice a week.Raise an exception for this release and continue to work on itLowLowIdentified
15SDC

 

Not able to update all the required vulnerabilities, as per general requirement 
Jira
serverONAP Jira
serverId425b2b0a-557c-3c0c-b515-579789cceedb
keyREQ-439
SDCContinuously monitor the vulnerabilities reported Raise an exception for this release and continue to work on itLowLowIdentified
16SDC

 

Code coverage fail to meet the required goal. Currently we are very close to the requirement of at least 55% of line coverage.SDCTrack code coverage closely and try to identify the changes that introduced drops and improve them.Raise an exception for this release and continue to work on itLowLowIdentified
17SDC

 

Not able to fix 

Jira
serverONAP Jira
serverId425b2b0a-557c-3c0c-b515-579789cceedb
keyOJSI-94
. Was identified that the issue requires a significant change in the front end of the workflow plugin in SDC. There is no resource for now to deal with the problem.

SDCTry to find resources in the community to work on the issue. The issue will be tracked twice a week during the release.Raise an exception for this release and continue to work on itHighLowIdentified