-
Notifications
You must be signed in to change notification settings - Fork 10
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
R24.03 Digital Product Pass DPP BatteryPass - Release Checks #511
Comments
We have a release candidate: https://github.com/eclipse-tractusx/digital-product-pass/releases/tag/v2.1.1 The TRGs were check for compliance in the following ticket: eclipse-tractusx/digital-product-pass#180 The Security Scans are all passed including Veracode (SCA and Code Scan). I have requested today the review from the Security Team.
I will inform here of the status of the reviews and findings |
Little remark here: eclipse-tractusx/digital-product-pass#224 There was a frontend import missing, so the basic E2E test of scanning a QR code was not working. We added it to the release candidate v2.1.1 in order for the E2E tests to be passed. The security scans have been done again and since nothing has changed they are passed. Today I had a meeting with @szymonkowalczykzf to talk about the Threat Modelling and this was informed there. He will add the security thread modelling in our repo in docs/security |
SCA and SAST and SecretScan approved |
Security Assessment Process (Threat Modeling Analysis) approved. Re-assessment was done on Wednesday 7th Feb 2024. All finding are properly addressed and mitigated. |
Thank you @BANANAS1337 and @szymonkowalczykzf! @RoKrish14 can you do the review to the IaC, Container Scan and DAST? |
@matbmoser - updates needed Findings:
Functional Findings:
Heads-up: the battery pass will not pass the 24.05. tests with the current implementation. Please review the Data Sovereignty Guidelines for 24.05. carefully to be able to pass 24.05. |
It was missing to move this ticket to Expert Review. I adjusted it to the current status of the ticket. |
We needed to re-release the tag because there was a mistake in the header licenses: The issue was raised here: eclipse-tractusx/digital-product-pass#231 There was no code changes, just comments in the files. We just request the security team @RoKrish14 to see the diff and re-approve the Security Aspects: eclipse-tractusx/digital-product-pass@v2.1.2...v2.1.3 In this release is also included the comments in the .trivyignore that were required to get the security approval before. We needed to fix the mistake in the header license. And it was done and now is good to go :) At the end in the release just the "Tractus-X" part was added. |
[v2.1.3] SAST: Approved |
Confirming "Compliant with relevant published CX Standards".
plus additionally and for the data model:
Furthere details are listed in the CX-0096 Triangle For Digital Product Pass. |
Confirming // Internal documentation
|
Confirming
|
Security Assessment Process (Threat Modeling Analysis) approved. Re-assessment was done on Wednesday 7th Feb 2024. All finding are properly addressed and mitigated. It will be uploaded later to the Docs part of the Product Pass Repo. |
As discussed earlier: since everything is the same as before approval it is approved |
INT test not performed/not documented. Updated 24-02-21 |
System team check concluded successfully eclipse-tractusx/digital-product-pass#180 Small issue with documentation in github needs clarification, but this should not affect the release |
Since the issue need further clarification and not affects the release I created a ticket to discuss that later: eclipse-tractusx/digital-product-pass#236 Therefore I will mark the TRGs as approved. |
I will include that as approved too |
Documentation existing and content is looking reasonable. Also no specific sovereignty requirement for 24.03.Expert Approval granted. Please consider the Q-Gate criteria for 24.05. have a good PI ! |
Thank you @vialkoje!! Marking Documentation as Approved then! Thank you very much everyone for the review! |
@kelaja are we ready to close this ticket? I am removing myself and all the other reviewers from the assignment. |
all pre-conditions fulfilled; |
Release Info
Please provide information on what you want to be included in the Eclipse Tractus-X release.
If you are not owner of this issue, please provide the information as comment to the issue.
Version to be included in Eclipse Tractus-X release:
App Version: v2.1.3
Chart Version: 2.1.4
Leading product repository: https://github.com/eclipse-tractusx/digital-product-pass
QG4 Review Date: 21.02.2024
Compliance Verifications
This issue tracks all compliance related checks, that need to be performed for a product release in Eclipse Tractus-X.
Documentation
Security Checks
General Checks
- R24.03 Digital Product Pass Tractus-X Release Guideline Check sig-infra#440
- QG 4 checks Release 24.03 digital-product-pass#180
Test Results
Helpful Links
The text was updated successfully, but these errors were encountered: