-
Notifications
You must be signed in to change notification settings - Fork 10
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
R24.03 Item Relationship Service (IRS) - Release Checks #494
Comments
Good morning @jjeroch, |
Good morning @vialkoje, The Tractus-X Release Guidelines Check is pending for QG4 R24.3. Tractus-X Release Guidelines Check Release 24.3: Documentation: Docu Thank you very much |
@kelaja please update the status based on the following information:
fyi @jzbmw |
@wjost, |
For Release R24.03 we do not support Targus-Release auf GXDCH. Hence „Gaia-X compliance“ is still on the level of R23.12. I confirm this release is GAIA-X compliant. |
Interoperability checksPreparation for Business Hour 19.2.2024 17:30 - 18:15 |
Threat Modeling Analysis passed@pablosec @scherersebastian |
Please fix these issues regarding the role of security minister @ds-jhartmann @ds-ext-kmassalski @dsmf (x) Container Scans passed
Expat library is not under our control, it is inside eclipse-temurin image, that we are using in Dockerfile. It is possible to manually update expat in the container with below command: Taking the above into account, we can only wait until there is a new eclipse-temurin image with an upgraded version of the expat library (probably soon, as JDK is already patched, waiting for JRE). CSRF security finding was fixed. |
Stand 14.02.2024 Static Application Security Testing (SAST) scans passed
Dynamic Application Security Testing (DAST) tests passedSecret Scans passed
Software Composition Analysis (SCA) passedVeraCode@klaudiaZF @ZFLokesh @RoKrish14 @Tim.herres Container Scans passed
Infrastructure as Code (IaC) scans passed |
INT test performed/documented. |
Hey! I'm done with the first round of checks and opened 2 issues that needs to be fixed. You can see more detail here. |
Documentation available and looking consistent - Expert Approval granted |
As PO I assure that no changes from an earlier release of the Interoperability aspects exists |
2 minor findings wrt TRGs => QG approval postponed |
Hey, I've closed the QG issue as all subtasks have been fixed. I approve the QG. The new versions are: AppVersion: |
SAST: Approved IAC: Pending |
Security Assessment Process (Threat Modeling Analysis) approved. No significant changes detected since last release. Documentation of the assessment will be moved out to the GitHub repositories of the Products before the next release. |
Hello @RoKrish14 |
@ds-mwesener @ds-mmaul presented me with the security dashboard to look at the results. Container Scans: Approved |
Hello
Thank you very much. |
QG4 approval granted. Congrats! |
Release Info
Please provide information on what you want to be included in the Eclipse Tractus-X release.
If you are not owner of this issue, please provide the information as comment to the issue.
Version to be included in Eclipse Tractus-X release:
Leading product repository:
IRS Repos
Compliance Verifications
This issue tracks all compliance related checks, that need to be performed for a product release in Eclipse Tractus-X.
Documentation
Security Checks
General Checks
Test Results
Helpful Links
The text was updated successfully, but these errors were encountered: