eclipse-tractusx / sig-release

https://eclipse-tractusx.github.io/sig-release
Apache License 2.0
8 stars 8 forks source link

Golden Record / BPN Service Release 23.12 Security Acceptance Criteria #95

Closed kelaja closed 9 months ago

kelaja commented 11 months ago

Release Security 23.12

Source in Catena-X Confluence and Expert Contacts here(Source only accessible for Catena-X Consortia members in current transition phase).

rybtim commented 10 months ago

Threat Modelling Analysis results were updated within last release 23.09 https://confluence.catena-x.net/x/Cm1HAw. No significant changes. Next update is planned in 24.03 with the upcoming breaking change of the generic endpoint and the implementation of the orchestrator. @guenterban

rybtim commented 10 months ago

Static Application Security Testing (SAST): No high risks found can you check @PiotrStys

rybtim commented 10 months ago

Dynamic Application Security Testing (DAST): The pen environment was setup for 21.12.2023 @PiotrStys can you check

rybtim commented 10 months ago

Software Composition Analysis (SCA): No high findings @klaudiaZF @Gitleena

rybtim commented 10 months ago

Container Scan conducted: No high findings @scherersebastian can you confirm

rybtim commented 10 months ago

Infrastructure as Code: No high findings @scherersebastian please confirm

PiotrStys commented 10 months ago

@rybtim, can you please provide the updated URL of the deployment?

guenterban commented 10 months ago

@kelaja: Threat Modelling Analysis passed

SujitMBRDI commented 9 months ago

@rybtim, can you please provide the updated URL of the deployment?

Please find below links for deployed Pen environment https://argo.dev.demo.catena-x.net/applications/argocd/bpdm-pen?view=tree&resource= https://business-partners-pen.dev.demo.catena-x.net/companies/test-company/ui/swagger-ui/index.html https://business-partners-pen.dev.demo.catena-x.net/pool/ui/swagger-ui/index.html

@nicoprow EDIT: I removed the bridge link. Only Gate and Pool are relevant for Pen-Testing

PiotrStys commented 9 months ago

@SujitMBRDI, @rybtim Sorry but this is not clear enough to me.

Are those URLs alternative deployments and is this enough to scan one of them? I believe that so far we used the one below for assessments: https://business-partners-pen.dev.demo.catena-x.net/pool

Does that seem to work for this QG as well?

klaudiaZF commented 9 months ago

Hi @SujitMBRDI , can you please provide a link to project name in Veracode for SCA ?

nicoprow commented 9 months ago

@SujitMBRDI, @rybtim Sorry but this is not clear enough to me.

Are those URLs alternative deployments and is this enough to scan one of them? I believe that so far we used the one below for assessments: https://business-partners-pen.dev.demo.catena-x.net/pool

Does that seem to work for this QG as well?

The last time we had two scans: One for the pool and one for the test-company subpath. These two would need to be executed again:

grafik
nicoprow commented 9 months ago

Hi @SujitMBRDI , can you please provide a link to project name in Veracode for SCA ?

Bildschirmfoto 2023-11-22 um 10 40 28
klaudiaZF commented 9 months ago

Hi All,

SCA passed

https://analysiscenter.veracode.com/auth/index.jsp#ReviewResultsSCA:47240:1405572:31074750:31044898:31060548:::::4421730:

PiotrStys commented 9 months ago

Hello,

No high/critical findings reported back by Invicti. Others have been reviewed and approved. image

DAST Passed

Thanks, Piotr

scherersebastian commented 9 months ago

IaC/ KICS passed. Container trivys scans passed

DnlZF commented 9 months ago

Hi, there are no open GitGuardian findings:

image

-> Secret scanning approved

Best regards Daniel