1/11/2021 Meeting
Akraino Security Sub-Committee Meeting Agenda 01/11/2021
Attendees:
Randy Stricklin
Brett Preston
Jim St. Leger
Pranab Bajpai
Daniil Egranov
Omogbolahan Alli
Tina Tsou
Agenda:
- Open forum to discuss CVE exception spreadsheet items with Blueprint owners.
- LFX Security Page Discussion
- Webinar on LFX Security on Jan 20th - https://lfx.linuxfoundation.org/resources/webinars/
- LFX Security site. https://security.lfx.linuxfoundation.org/#/
- How LFX Security relates to the Akraino project
- What tools are used?
- How are repos scanned and how are these repos determined?
- Missing manifest file, LFX security cannot scan for vulnerabilities
- Example: https://docs.google.com/document/d/1nYIAQ--Xk3hTkpeZ0NiAnhWk5rtTY_7HyY6GkdOKnsU/edit
- Show manifest samples pdf file.
- Full list of repos below:
- Akraino-edge-stack - https://github.com/akraino-edge-stack/starlingx
- Akraino-edge-stack - https://github.com/akraino-edge-stack/redfish
- Akraino-edge-stack - https://github.com/akraino-edge-stack/ta-ipa-deployer
- Akraino-edge-stack - https://github.com/akraino-edge-stack/ta-caas-helm
- Akraino-edge-stack - https://github.com/akraino-edge-stack/nc-seba
- Akraino-edge-stack - https://github.com/akraino-edge-stack/ta-monitoring
- Akraino-edge-stack - https://github.com/akraino-edge-stack/ta-lockcli
- Akraino-edge-stack - https://github.com/akraino-edge-stack/connected-vehicle
- Akraino-edge-stack - https://github.com/akraino-edge-stack/ta-rpmbuilder
- Akraino-edge-stack - https://github.com/akraino-edge-stack/ta-remote-installer
- Akraino-edge-stack - https://github.com/akraino-edge-stack/yaml_builds
- Akraino-edge-stack - https://github.com/akraino-edge-stack/ta-distributed-state-server
- Akraino-edge-stack - https://github.com/akraino-edge-stack/ta-config-manager
- Akraino-edge-stack - https://github.com/akraino-edge-stack/ta-storage
- Akraino-edge-stack - https://github.com/akraino-edge-stack/kni-templates
- Akraino-edge-stack - https://github.com/akraino-edge-stack/ta-infra-ansible
- Akraino-edge-stack - https://github.com/akraino-edge-stack/ta-access-management
- Akraino-edge-stack - https://github.com/akraino-edge-stack/ta-hw-detector
- Akraino-edge-stack - https://github.com/akraino-edge-stack/ta-caas-install
- Akraino-edge-stack - https://github.com/akraino-edge-stack/ta-hostcli
- Akraino-edge-stack - https://github.com/akraino-edge-stack/ta-cm-plugins
- Akraino-edge-stack - https://github.com/akraino-edge-stack/ta-yarf
- Akraino-edge-stack - https://github.com/akraino-edge-stack/rec
- Akraino-edge-stack - https://github.com/akraino-edge-stack/ta-caas-logging
- Akraino-edge-stack - https://github.com/akraino-edge-stack/ta-ironic-virtmedia-driver
- How LFX Security relates to the Akraino project
3. Ensure BluVal tools are updated regularly.