Closed lolaapenna closed 2 months ago
ORA backlog planning
For ORA Backlog
Milestone: PoC Feature: Asset & Issue (Vulnerability) Discovery
Heureka PoC Demo
Heureka PoC Implementation UI
Heureka
Implement Image Registry Scanner
Implement Heureka NVD Advisory Scanner
Implement Kubernetes Container Scanner
Implement Heureka Issue Matches
Implement Authentication
Takt 10
Epics
Features GH Backend Plugin (connecting Heureka core and Heureka scanners) (Refined) Scanner Blueprint Remediation Tracking
Epics
Activity Management
Remediation Tracking
Evidence Management
GH Backend Plugin (connecting Heureka core and Heureka scanners)
(Refined) Scanner Blueprint
Refined PoC - Deployment + fully functional GH plugins with possibility to use multiple scanners reporting to Heureka - Epics: interconnection of plugins FE/BE, Deployment,scanners and core-GH enablement (config interface, env vars), enable multiple clusters for the scanners (design discussion needed).
enable use in GH
Refine Issue Matcher - historical tracking (poc - we wipe db after every scan) - epic: scan tracking, authentication done, created-by relation attribute to the entities (other attributes too)
Takt 10 Features/Milestones:
Refined PoC: Solve the limitations of the PoC Epics:
- Implement interconnection of Heureka Core and Scanners in GH
- Enable Multiple Clusters for the Scanners
- Deployment of the Scanners
Refined Issue Matcher: Enhance the Issue Matcher service Epics:
- Implement 'created-by' Relationship on all Entities (new relationships emerging from the issue matcher service)
- Implement Historial Tracking
Context The feature addresses the limitations of the current PoC
The PoC focuses on asset and issue discovery, providing vulnerability insights for Kubernetes and container images. Key components include:
Kubernetes Scanners: Identifying Kubernetes assets Image Registry Scanners: Identifying image assets NVD Integration: Fetching published CVEs. Issue Matcher Service: Match CVEs to affected component versions and UI Implementations: Component, service, and issue match views equipped with search and filter capabilities
The Limitations
- Interconnectivity of the scanners and heureka core in GH
- Not all clusters can be scanned
- The issue matcher History tracking is not enabled leading to database wipes after each scan to avoid duplicate matches.
Sprint 8/24 Retrospective - 27th August 2024
Duration Jul 29 - Aug 23
Planned Epics
Closed Epics:
Touched Epics:
Untouched Epics
Sprint 9/24 Planning
Duration Aug 24 - Sep 20
Availability:
Rolled-over Epics – Touched Epics from 8/24
Moved Epics – Untouched Epics from 8/24
Planned Epics
Side Notes: FW: -Seed User ticket -one time scan to insert data.