eclipse-tractusx / sig-release

https://eclipse-tractusx.github.io/sig-release
Apache License 2.0
8 stars 10 forks source link

R24.03 - Eclipse Data Space Connector (EDC) Release Checks #491

Closed kelaja closed 7 months ago

kelaja commented 9 months ago

Release Info

Please provide information on what you want to be included in the Eclipse Tractus-X release. If you are not owner of this issue, please provide the information as comment to the issue.

Version to be included in Eclipse Tractus-X release: 0.5.x

Leading product repository: repository link

Compliance Verifications

This issue tracks all compliance related checks, that need to be performed for a product release in Eclipse Tractus-X.

Documentation

Security Checks

General Checks

Test Results

Helpful Links

stefan-ettl commented 8 months ago

SAST Scan done - no findings:

Bildschirmfoto 2024-02-19 um 10 59 30
stefan-ettl commented 8 months ago

SCA Scan done - no findings: image

stefan-ettl commented 8 months ago

Container Scan with Trivy - passed: https://github.com/eclipse-tractusx/tractusx-edc/actions/runs/7931952515

stefan-ettl commented 8 months ago

Since there was only a Patch regarding Bugfixes, no change in regards to compliance.

Gaia-X compliance confirmed GDPR compliance confirmed (personal data, data protection + privacy DPP) Interoperability checks performed Data Sovereignty checks performed Compliant with relevant published CX Standards (see the Catena-X standard library)

stefan-ettl commented 8 months ago

Since there was only a Patch regarding Bugfixes, no change in regards to Documentation: @vialkoje could you please confirm? Arc24 documentation up-to-date Administrators Guide up-to-date End-User manual up-to-date Interface documentation up-to-date

stefan-ettl commented 8 months ago

Secret Scans of 0.5.4 - no findings.

stefan-ettl commented 8 months ago

Thread Modelling Analysis passed - no change in regards to the last release. @pablosec can you confirm?

wolf4ood commented 8 months ago

Latest tests Run with IaC tests

https://github.com/eclipse-tractusx/tractusx-edc/actions/runs/7958280287

vialkoje commented 8 months ago

as there was no change, documentation is sufficient. Expert approval granted

FaGru3n commented 8 months ago

@vialkoje

as there was no change, documentation is sufficient. Expert approval granted

Documentation

  • [ ] Arc24 documentation up-to-date
  • [ ] Administrators Guide up-to-date
  • [ ] End-User manual up-to-date
  • [ ] Interface documentation up-to-date

all of them?

stefan-ettl commented 8 months ago

TRGs completed in 23.12 - no code change since then. https://github.com/eclipse-tractusx/tractusx-edc/issues/885

stefan-ettl commented 8 months ago

Style Guide is n.a. because the EDC has no frontend.

stefan-ettl commented 8 months ago

User Journey approved by PO because there is no BO for the EDC.

RoKrish14 commented 8 months ago

Quality Gate check performed with @wolf4ood:

SAST: Approved SCA: Approved DAST: Approved Secret Scans: Approved IAC: Approved Container scans: Approved

DirkBTSI commented 8 months ago

INT test not performed/not documented. E2E test not performed/not documented. EDC is directly "co-tested" by some systems during the execution of the E2E test. No high defect. TM approved @kelaja : please approve for "E2E Integration Test passed"

stefan-ettl commented 8 months ago

Interoperability checks performed Data Sovereignty checks performed no change compared to 0.5.x Gate Review in December - therefore valid for 24.03 as well.

RolaH1t commented 8 months ago

QG review performed in question => TRG / will be confirmed with System team, as EDC version 0.5.x was already part of R24.03

szymonkowalczykzf commented 8 months ago

Security Assessment Process (Threat Modeling Analysis) approved.

No significant changes detected since last release. No open critical & high finding remaining for this release.

Documentation of the assessment will be moved out to the GitHub repositories of the Products before the next release.

FaGru3n commented 8 months ago

Question to TRG if this is still needed https://github.com/eclipse-tractusx/tractusx-edc/issues/885 while TRG updates?

RolaH1t commented 8 months ago

QG4 approval granted. Congrats!