eclipse-tractusx / sig-release

https://eclipse-tractusx.github.io/sig-release
Apache License 2.0
9 stars 10 forks source link

R24.03 Catena-X Portal - Release Checks #499

Closed kelaja closed 8 months ago

kelaja commented 9 months ago

Release Info

Please provide information on what you want to be included in the Eclipse Tractus-X release. If you are not owner of this issue, please provide the information as comment to the issue.

Version to be included in Eclipse Tractus-X release: 1.8.0

Portal:

IAM:

Leading product repository: https://github.com/eclipse-tractusx/portal

Compliance Verifications

This issue tracks all compliance related checks, that need to be performed for a product release in Eclipse Tractus-X.

Documentation

https://github.com/eclipse-tractusx/sig-release/issues/499#issuecomment-1961635593

Security Checks

https://github.com/eclipse-tractusx/sig-release/issues/499#issuecomment-1970832097

General Checks

Test Results

Helpful Links

evegufy commented 9 months ago

added preliminary release info (version still in release candidate / e2e-testing phase)

jjeroch commented 9 months ago

@kelaja please update the status based on the following information:

Ongoing:

wjost commented 9 months ago

As agreed for R24.3 nothing will be changed. CX is still sticking to pre targus release. I confirm this solution is still GX compliant.

ThomasObermeyer commented 9 months ago

Interoperability check has already been done in last release; still valid - since there are no major architecture changes.

evegufy commented 9 months ago

@guenterban @RoKrish14 could you please perform the security checks?

szymonkowalczykzf commented 9 months ago

Security Assessment Process (Threat Modeling Analysis) approved.

Re-assessment was done on Tuesday 13th Feb 2024. No open findings remains. Documentation of the assessment will be updated in the Portal docs repo soon.

BANANAS1337 commented 9 months ago

SCA: Approved SAST: Approved

evegufy commented 9 months ago

@guenterban @RoKrish14 could you please perform the security checks?

Please check the following scans or tools:

And please let me know if you need additional information. I've checked and as your anyway checking the state yourself, I'm not very keen on posting here screenshots of the security scans.

RoKrish14 commented 9 months ago

DAST: Approved Secret Scans : Approved Infrastructure as Code (IaC): Approved

vialkoje commented 9 months ago

could you please add the links to the documentation documents to check ?

Arc24 documentation Administrators Guide End-User manual Interface documentation

DirkBTSI commented 9 months ago

INT test not performed/not documented. E2E test performed/documented. Three (3) high defect. TM not approved

Update 2024-03-04: Three (3) high defects - solved in meantime. TM approved @kelaja : please approve for "E2E Integration Test passed"

jjeroch commented 9 months ago

could you please add the links to the documentation documents to check ?

Arc24 documentation Administrators Guide End-User manual Interface documentation

@vialkoje we shared those last week wednesday via mail

System Docu
https://github.com/catenax-ng/tx-portal-assets/tree/main/docs

Helm Chart Docu
https://github.com/eclipse-tractusx/portal-cd/blob/main/charts/portal/README.md

Ticket in welchem du bitte schriftlich ein „ok“ dalassen musst.
https://github.com/eclipse-tractusx/sig-release/issues/499
jjeroch commented 9 months ago

Data Sovereignty checks performed - successful

jjeroch commented 9 months ago

Compliant with relevant published CX Standards => agreed

RolaH1t commented 9 months ago

Compliant with relevant published CX Standards => agreed

thx

RolaH1t commented 9 months ago

Data Sovereignty checks performed - successful

can you pls add any evidence (like screenshot etc)?!

RolaH1t commented 9 months ago

Data Sovereignty 4x Documentation SEC: Container Scans TRGs (due to final version) Test Mgmt approval pending closure of final test cases. Code update expected => therefore SEC scans need to be re-confirmed based on final code version. QG approval postponed.

RoKrish14 commented 9 months ago

Container Scans: Approved

vialkoje commented 8 months ago

Documentation existing and looking consistent. No specific sovereignty requirements for 24.03 expert approval granted. Please add links to docs to the ticket next time and consider QGate criteria sovereignty for 24.05 !

evegufy commented 8 months ago

@SebastianBezold @FaGru3n could you please check the TRGs?

evegufy commented 8 months ago

@RoKrish14 could you please perform the security checks again?:

Just ping once you want you check the security tab. Thank you!

evegufy commented 8 months ago

@SebastianBezold @FaGru3n could you please check the TRGs?

FYI, I created https://github.com/eclipse-tractusx/portal-cd/issues/203

RoKrish14 commented 8 months ago

Following re-request from @evegufy :

SCA: Approved SAST: Approved Secret Scans: Approved DAST: Approved Container Scans: Approved IAC: Approved

RolaH1t commented 8 months ago

@SebastianBezold with @FaGru3n on vacation this week, pls prioritize the completion of this TRG issue by 06-Mar latest, as we are approaching the March Release milestone on Friday. Thx, Roland

SebastianBezold commented 8 months ago

Hi @RolaH1t,

the TRG checks are done. There is one issue, violating a TRG. See eclipse-tractusx/portal#207. The team does not want to fix it for this release. See the specific issue comment So i'll close the TRG QG issue from my side and leave it up to you to decide, if it has to be fixed or if it can wait for next release

evegufy commented 8 months ago

Hi @RolaH1t see clarification, severity-wise this is not at all a topic which needs to be forced into the release.

evegufy commented 8 months ago

@Siegfriedk for writing the changelog: those are the final released versions for 24.03:

Final 24.03 versions

Portal

Portal Chart: portal-1.8.0

Portal Frontend: v1.8.0

Portal Backend: v1.8.0

Portal Assets: v1.8.0

Portal Frontend Registration: v1.6.0

IAM

CentralIdP: centralidp-2.1.0

SharedIdP: sharedidp-2.1.0

RolaH1t commented 8 months ago

all pre-conditions fulfilled => QG approval granted! Congrats ;-)