Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

R24.03 Trace-X - Release Checks #506

Closed
20 tasks done
Tracked by #610
kelaja opened this issue Jan 30, 2024 · 28 comments
Closed
20 tasks done
Tracked by #610

R24.03 Trace-X - Release Checks #506

kelaja opened this issue Jan 30, 2024 · 28 comments
Assignees
Labels
compliance RM compliance documentation RM documentation trace-x Feature/Bug for Trace-x component
Milestone

Comments

@kelaja
Copy link
Contributor

kelaja commented Jan 30, 2024

Release Info

Please provide information on what you want to be included in the Eclipse Tractus-X release.
If you are not owner of this issue, please provide the information as comment to the issue.

Version to be included in Eclipse Tractus-X release:

Helm Chart Version: 1.3.28
App Version: 10.3.0

Leading product repository:

Compliance Verifications

This issue tracks all compliance related checks, that need to be performed for a product release in Eclipse Tractus-X.

  • Gaia-X compliance confirmed
  • Note: @wjost requested approval
  • GDPR compliance confirmed (personal data, data protection + privacy DPP)
  • Requested Jens Weiss for approval based on R23.12
  • Interoperability checks performed
  • Note: Business Hours on 19.2.2024
  • Data Sovereignty checks performed
  • Note: Business Hours on 19.2.2024 - alignment with @vialkoje
  • Compliant with relevant published CX Standards (see the Catena-X standard library)

Documentation

  • Arc24 documentation up-to-date
  • Alignment in progress with @vialkoje
  • Administrators Guide up-to-date
  • Alignment in progress with @vialkoje
  • End-User manual up-to-date
  • Alignment in progress with @vialkoje
  • Interface documentation up-to-date
  • Alignment in progress with @vialkoje

Security Checks

  • Threat Modeling Analysis passed
  • Note: Requested SecOps team for approval on base of R23.12
  • Static Application Security Testing (SAST) scans passed
  • Dynamic Application Security Testing (DAST) tests passed
  • Secret Scans passed
  • Software Composition Analysis (SCA) passed
  • Container Scans passed
  • Infrastructure as Code (IaC) scans passed

General Checks

Test Results

  • E2E Integration Test passed
  • Note: @ds-alexander-bulgakov covering approval of E2E with testmanagement
  • User Journey approved

Helpful Links

@mkanal
Copy link

mkanal commented Feb 13, 2024

Hello @vialkoje

Documentation:

Docu
Arc24 documentation
Administrators Guide
End-User manual
Interface documentation

Thank you very much
Martin

@mkanal
Copy link

mkanal commented Feb 13, 2024

@kelaja please update the status based on the following information:

  • "User Journey approved": User Journey has not changed since release 23.12. For this reason, the approval of the User Journey is based on the approval given by BO of R23.12.
  • GDPR compliance confirmed - There is no change since release 23.12 regarding the processing ans storing of GDPR related data (personal data, data protection + privacy DPP) For this reason, the approval of the User Journey is based on the approval given by GDPR experts of R23.12.

fyi @jzbmw

@mkanal
Copy link

mkanal commented Feb 13, 2024

@wjost,
kindly ask for your approval regarding Gaia-X compliance. There are no changes between 24.3 and already approved version 23.12.
Thank you very much
Martin

@wjost
Copy link

wjost commented Feb 13, 2024

For Release R24.03 we do not support Targus-Release auf GXDCH. Hence „Gaia-X compliance“ is still on the level of R23.12. I confirm this release is GAIA-X compliant.

@mkanal
Copy link

mkanal commented Feb 13, 2024

Interoperability checks

Preparation for Business Hour 19.2.2024 17:30 - 18:15
Participants @jzbmw & @mkanal
https://confluence.catena-x.net/display/PL/2024-02-12+InterOp+for+TraceX+and+IRS

@mkanal
Copy link

mkanal commented Feb 13, 2024

Threat Modeling Analysis passed

@pablosec @scherersebastian
There are no relevant changes in either product compared to R23.12. For this reason, we would like to request the release of the QGC "Threat Modelling Analysis passed" based on the R23.12 release.

@mkanal
Copy link

mkanal commented Feb 14, 2024

Data Sovereignty checks performed

@vialkoje @cwBMW
Data Sovereignty Guardrails for Release 24-03 referring to the QG or Q-Gate Criteria Release 23-12. As Trace-X has an approval of Data Sov Guardrails for R23.12 this approval might be valid for R24.3 as well.
Trace-X team participates in Data Sov Weekly on Monday 19.2 to discuss the Data Sov of the product.
Kindly ask for approval of Data Sovereignty

@mkanal
Copy link

mkanal commented Feb 14, 2024

Date: 14.2.2024

Static Application Security Testing (SAST) scans passed

@BANANAS1337 @RoKrish14

  • @ds-mmaul Please add mitigation comment for 3 medium findings
  • code must be scanned weekly with Veracode tool
  • medium risks require mitigation statement @ds-mmaul
  • only medium findings

image

image

Dynamic Application Security Testing (DAST) tests passed

Backend

image

image

Secret Scans passed

@DnlZF

Software Composition Analysis (SCA) passed

VeraCode

@klaudiaZF @ZFLokesh @RoKrish14 @Tim.herres
Dependencies must be scanned with Veracode tool in regard to vulnerability

  • no high findings

image

Container Scans passed

@RoKrish14

Infrastructure as Code (IaC) scans passed

@RoKrish14

@jjeroch jjeroch self-assigned this Feb 14, 2024
@jjeroch jjeroch added this to Portal Feb 14, 2024
@github-project-automation github-project-automation bot moved this to NEW USER REQUEST in Portal Feb 14, 2024
@jjeroch jjeroch moved this from NEW USER REQUEST to IN PROGRESS in Portal Feb 14, 2024
@jjeroch
Copy link

jjeroch commented Feb 14, 2024

Findings UI/UX

  • update icon used for "Queued & Requested" Quality Investigations. Suggested Icon (Material UI):
    Image

  • QUALITY INVESTIGATIONS table

    • missing frame on right and left side
    • button "view all" is unclear - I can see no-where how many records are even available - please add somewhere the information of record numbers
    • button "view all" is also displayed if the table has "0" records; in this case I suggest to disable the button/option
  • same as the bullet points above also applies for QUALITY ALERTS

  • used colors unclear - please recheck
    Image
    Image

  • Navigation: please use checkboxes for such navigations where multiple selects are possible. Current used element is a single select element
    Image

  • Overlay implementation does not follow the guidelines of cx
    Image

  • User Infos: "createAlert" tooltip info unclear
    Image

  • User direction - why does clicking "closed" on the right hand side results into such an overlay of investigation closure? Unclear
    Image


Functional Request
Where can I find the details of the policies - I do not understand those policy details
Image

@ds-mmaul
Copy link

ds-mmaul commented Feb 16, 2024

Date: 14.2.2024

Static Application Security Testing (SAST) scans passed

  • @ds-mmaul Please add mitigation comment for 3 medium findings in frontend

  • code must be scanned weekly with Veracode tool

  • medium risks require mitigation statement @ds-mmaul

  • only medium findings

image

image

Dynamic Application Security Testing (DAST) tests passed

Backend

image

image

Secret Scans passed

Software Composition Analysis (SCA) passed

VeraCode

Dependencies must be scanned with Veracode tool in regard to vulnerability

  • no high findings

image

Container Scans passed

Infrastructure as Code (IaC) scans passed

proposed mitigation for all three medium findings

@BANANAS1337
Copy link

SCA: Approved
SAST: Approved

@almadigabor
Copy link

My first round of checks have been completed here. I've opened 2 small issues that needs fixing before I approve the QG.

@vialkoje
Copy link

Expert Approval granted - documents existing and looking consistent

@DirkBTSI
Copy link

INT test performed/documented.
E2E test performed/documented.
No high defect.
TM approved
@kelaja : please approve for "E2E Integration Test passed"

@mkanal
Copy link

mkanal commented Feb 20, 2024

image

@jzbmw
Copy link

jzbmw commented Feb 20, 2024

As the PO i assure that in this minor release there have not been changes regarding interoperability to a earlier version

@RolaH1t
Copy link
Contributor

RolaH1t commented Feb 20, 2024

Secret scans pending
2 minor findings wrt TRGs
StyleGuide findings must be rated (critical?)
QG approval postponed until those topics are addressed

@mkanal
Copy link

mkanal commented Feb 20, 2024

Hello @DnlZF
could you please approve the secrets scanning for product Trace-X. Thank you very much, Martin

@DnlZF
Copy link

DnlZF commented Feb 20, 2024

Secret scans: approved

@jzbmw
Copy link

jzbmw commented Feb 20, 2024

Findings UI/UX

  • update icon used for "Queued & Requested" Quality Investigations. Suggested Icon (Material UI):
    Image

  • QUALITY INVESTIGATIONS table

    • missing frame on right and left side
    • button "view all" is unclear - I can see no-where how many records are even available - please add somewhere the information of record numbers
    • button "view all" is also displayed if the table has "0" records; in this case I suggest to disable the button/option
  • same as the bullet points above also applies for QUALITY ALERTS

  • used colors unclear - please recheck
    Image
    Image

  • Navigation: please use checkboxes for such navigations where multiple selects are possible. Current used element is a single select element
    Image

  • Overlay implementation does not follow the guidelines of cx
    Image

  • User Infos: "createAlert" tooltip info unclear
    Image

  • User direction - why does clicking "closed" on the right hand side results into such an overlay of investigation closure? Unclear
    Image

Functional Request Where can I find the details of the policies - I do not understand those policy details Image

The Frontend findings will be refactored with the Release 24.05. With the major release we plan to implement further bigger frontend changes.

@almadigabor
Copy link

I'm done with the QG checks, all issues have been fixed, I approve it.

@mkanal
Copy link

mkanal commented Feb 20, 2024

Findings UI/UX

  • update icon used for "Queued & Requested" Quality Investigations. Suggested Icon (Material UI):
    Image

  • QUALITY INVESTIGATIONS table

    • missing frame on right and left side
    • button "view all" is unclear - I can see no-where how many records are even available - please add somewhere the information of record numbers
    • button "view all" is also displayed if the table has "0" records; in this case I suggest to disable the button/option
  • same as the bullet points above also applies for QUALITY ALERTS

  • used colors unclear - please recheck
    Image
    Image

  • Navigation: please use checkboxes for such navigations where multiple selects are possible. Current used element is a single select element
    Image

  • Overlay implementation does not follow the guidelines of cx
    Image

  • User Infos: "createAlert" tooltip info unclear
    Image

  • User direction - why does clicking "closed" on the right hand side results into such an overlay of investigation closure? Unclear
    Image

Functional Request Where can I find the details of the policies - I do not understand those policy details Image

Hello @jjeroch ,
complete feedback is covered in pbis:
https://github.com/orgs/eclipse-tractusx/projects/45/views/1?filterQuery=label%3Auux
Thank you very much
Martin

@szymonkowalczykzf
Copy link

Security Assessment Process (Threat Modeling Analysis) approved.

No significant changes detected since last release.
No open critical & high finding remaining for this release.

Documentation of the assessment will be moved out to the GitHub repositories of the Products before the next release.

@RoKrish14
Copy link

DAST: Approved

For below approval, based on discussion with @ds-mmaul and @ds-mwesener -
Container Scans: Approved
IAC: Approved

@DnlZF DnlZF removed their assignment Feb 21, 2024
@RolaH1t
Copy link
Contributor

RolaH1t commented Feb 23, 2024

@mkanal , @jzbmw , @jjeroch what is your conclusion on StyleGuide pls?
All other Q-criteria are passed.

@jjeroch
Copy link

jjeroch commented Feb 27, 2024

@mkanal , @jzbmw , @jjeroch what is your conclusion on StyleGuide pls? All other Q-criteria are passed.

Based on Johannes comment above, provisional approval was granted. In release 24.05. the review MUST get scheduled earlier and findings must get fixed in time

@RolaH1t
Copy link
Contributor

RolaH1t commented Feb 27, 2024

pre-conditions all fulfilled;
QG approval granted!
Congrats!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
compliance RM compliance documentation RM documentation trace-x Feature/Bug for Trace-x component
Projects
Archived in project
Status: Done
Development

No branches or pull requests