eclipse-tractusx / sig-release

https://eclipse-tractusx.github.io/sig-release
Apache License 2.0
8 stars 8 forks source link

R24.03 Policy Hub / Certificate Hub - Release Checks #504

Closed kelaja closed 5 months ago

kelaja commented 7 months ago

Release Info

Please provide information on what you want to be included in the Eclipse Tractus-X release. If you are not owner of this issue, please provide the information as comment to the issue.

Version to be included in Eclipse Tractus-X release: 0.1.0 Leading product repository: https://github.com/eclipse-tractusx/policy-hub

Compliance Verifications

This issue tracks all compliance related checks, that need to be performed for a product release in Eclipse Tractus-X.

Documentation

https://github.com/eclipse-tractusx/sig-release/issues/504#issuecomment-1961701620

Security Checks

General Checks

Test Results

Helpful Links

evegufy commented 7 months ago

added preliminary release info (version still in release candidate / e2e-testing phase)

jjeroch commented 6 months ago

@kelaja please update the status based on the following information:

Ongoing:

wjost commented 6 months ago

These two components are only internal services not meant to share policies outside Catena-X. Hence not relevant for GAIA-X compliance.

evegufy commented 6 months ago

@guenterban @RoKrish14 could you please perform the security checks?

evegufy commented 6 months ago

@guenterban @RoKrish14 could you please perform the security checks?

Please check the following scans or tools:

And please let me know if you need additional information. I've checked and as your anyway checking the state yourself, I'm not very keen on posting here screenshots of the security scans.

RoKrish14 commented 6 months ago

SAST: Approved SCA: Approved DAST: Approved Secret Scans: Approved Infrastructure as Code (IaC): Approved

jjeroch commented 6 months ago

@vialkoje we shared those last week Wednesday via mail

System Docu https://github.com/eclipse-tractusx/policy-hub/tree/main/docs/technical-documentation

Ticket in welchem du bitte schriftlich ein „ok“ dalassen musst. https://github.com/eclipse-tractusx/sig-release/issues/504

jjeroch commented 6 months ago

Data Sovereignty checks performed - successful

jjeroch commented 6 months ago

Compliant with relevant published CX Standards => agreed

RolaH1t commented 6 months ago

Data Sovereignty checks performed - successful

pls add relevant evidence here as well

szymonkowalczykzf commented 6 months ago

Threat Modeling (Security Assessment Process) - Approved The assessment was done on 13 & 16 February 2024.

There is no open critical & high findings.

Assessment documentation will be uploaded into the GitHub Repository of Policy-Hub in near future.

RolaH1t commented 6 months ago

QG postponed, due to InterOp DataSov & Docu ThreatModeling & Container Scans and TRGs

RoKrish14 commented 6 months ago

@evegufy Container Scans: Approved

vialkoje commented 6 months ago

Documentation existing and looking consistent, Sovereignty requirements for 24.03 fulfilled. Expert Approval Granted.

Next release please add the Links to the ticket directly and consider the 24.05 Quality gate criteria ! have a good PI !

carslen commented 6 months ago

TRG check passed. Approval granted.

RolaH1t commented 6 months ago

Hi @evegufy (and @jjeroch ) what`s your plan to finalize Interoperability here? This is the only open item for the QG...

ThomasObermeyer commented 6 months ago

@kelaja Reviewed PolicyHub solution from a Interoperability perspective.

Conclusion: The solution is a helper tool that allows to create ODRL compliant policy description based on requester input. There are no interoperability requirements at this point in time that need to get met.

Approved from interoperability PoV for release 24.03

evegufy commented 6 months ago

Hi @evegufy (and @jjeroch ) what`s your plan to finalize Interoperability here? This is the only open item for the QG...

Hi @RolaH1t done https://github.com/eclipse-tractusx/sig-release/issues/504#issuecomment-1971007283

RolaH1t commented 6 months ago

all pre-conditions fullfilled QG approval granted Congrats

evegufy commented 6 months ago

@Siegfriedk for writing the changelog:

Final 24.03 version

Policy Hub: 0.1.0