Skip to main content

Community Office Hour 2024-04-05

Sebastian Bezold
Consortia System Team Member

Office Hour meeting minutes

System team

  • Several TRGs in Draft
    • See TRG 0
    • Dedicated PRs will be raised to gather feedback before publishing

Security team

  • Veracode license finally expired
    • Dashboards still accessible
    • No new scans can be run
    • CodeQL is the replacement
  • Security TRGs live. See the "TRG 8 - Security" section in Release Guidelines

FOSS

  • n/a

Open planning / community

  • n/a

Discussions

  • Dependabot PRs
    • In general: keep your dependencies up to date. Keep the DEPENDENCIES file in mind. Ask committers for help, if you don't have one in your team.
    • Specifically Docker base images: If dependabot suggests to upgrade the base image to a new major library version, that you do not support. Ask a committer to tell dependabot to ignore the dependency
    • Specifically Chart Releaser Action: Should not be an issue, but we can investigate if the upgrade would raise issues (1.4.1 to 1.6.0 in this case)
  • Are there updates to API versioning
    • No one in the call had an update
    • The Discussion is untouched for a while
    • If this is an issue for anyone, please push that topic again

Security Office Hour 2024-03-28

Consortia Security Team Member

Security Office Hour meeting minutes

Announcements

  • SAST:
    • Veracode - Offboarding: Last reminder, license terminates on 30-March-2024
    • CodeQL - Onboarding- Workflow Setup: TRG 8.01
  • DAST security scans are not part of the next release 24.05 (Updates will follow through the QG Acceptance Criteria)
  • KICS, Trivy, GitGuardian and Dependabot tools will continue as it is.

Community Office Hour 2024-03-22

Sebastian Bezold
Consortia System Team Member

Office Hour meeting minutes

System team

  • Investigating slow website build times
    • Local builds (and CI) take increasingly more time (~13 min for static build with empty caches)
    • Heap size has to be increased on some machines
    • Potential source: Versioning of the KITS and keeping all the versions

Security team

  • Some teams are already migrating from Veracode to CodeQL. Great! Remember to also remove Veracode workflows in this case.
  • PR to publish the Security TRG section will be raised
  • Snyk will not be part of the Security TRGs and therefore not mandatory. Best practices and how-tos will still be provided in sig-security

FOSS

  • Getting started guide improved
    • Does make it easier for new-joiners
    • Please link to this guide instead of duplicating information
    • If anything is missing, feel free to raise a PR or open an issue

Open planning / community

  • Tractus-X "Stammtisch Munich". See Matrix post
  • Old consortia office hour meeting will be cancelled. Open meeting link is now well known.

Discussions

  • People have been receiving on- and offboarding emails for the Tractus-X contributor team in GitHub
    • Unclear what triggered it
    • If you are committer, you don't need to also be part of the contributor group
    • In case you lost a necessary group assignment, please reach out

Community Office Hour 2024-03-15

Fabian Grün
Consortia System Team Member

Office Hour meeting minutes

System team

Security team

FOSS

  • Congrats to Rohan Krishnamurthy as a new committer in our community.
  • No open feedback or veto to archiving repositories that are out of purpose

Open planning / community

  • Current planning around the 2. Community Days Event, feel free to join
  • Infosession Processes, Methods Tools for next release 24.08 will present on monday planning meeting

Open Discussions

  • Committer Matrix Chatroom i now available for us within the Eclipse Tractus-X.
  • Release Day information to release day insights (YouTube)
    • Impressions for release process from Hanno, new standards and topics like SSI and further breaking changes
    • Working together with the community

Security Office Hour 2024-03-14

Consortia Security Team Member

Security Office Hour meeting minutes

Announcements

  • SAST: CodeQL transition is ongoing, PRs to add corresponding workflows is ongoing. Veracode license will expire at the end of March, so everyone is encouraged to review their workflows to ensure a timely transition to CodeQL.
  • DAST: Invicti license will expire at the end of August and already exceeded the website limit. There will be no DAST tool required for the next Quality Gate.
  • Secret scanning
    • Gitguardian is currently set up, but Gitleaks is a potential successor.
    • Testing of Github secret scanning is still in progress.
  • TRG 8.0 has been published as a draft, adjustments as PR are warmly welcome.

Open Discussions

  • none

Community Office Hour 2024-03-08

Gabor Almadi
Consortia System Team Member

Office Hour meeting minutes

System team

  • n/a

Security team

  • TRG 8.01, 8.03, 8.04, 8.05 first drafts are created, final versions will come soon
  • Be patient with CodeQL, could be tedious since it does provide a lot of findings

FOSS

  • New commiter election is open for Rohan Krishnamurthy. Please visit the page and make your vote!

Open planning / community

  • Role of the committer is being discussed, it will be presented in the next committer meeting. Basic role descriptions come from the Eclipse Foundation, but we want to specify in Tractus-X what else can be expected from a contributor, commiter and project lead.
  • Association release process and Eclipse Tractus-X needs to be aligned as the first is managed by the association and the second should be driven by the community.

Open Discussions

  • We should align on how and where a migration documentation should be created for products. This would ensure that upon Breaking Changes the upgrade processes can run smoothly with a guide available for everyone. The guide could include property, configuration, API changes and everything else that would affect the upgrade process from and old version to the new. A draft will be available on a working model that could be implemented by the products soon. A TRG could include information on where these guide should be located and in which format.

Community Office Hour 2024-03-01

Consortia System Team Member

Tractus-X Office Hour meeting minutes

System team

  • Docusaurus: Please use "toc_min_heading_level" and "toc_max_heading_level" to adjust your TOC
  • The community has to transparently describe our post-consortia release process

Security team

FOSS

  • Reminder: please make sure to attribute your "foreign" logos correctly

Open planning / community

  • second Eclipse Tractus-X Community days will take place 16-17 May 2024:
    • please provide your "wishes" for topics
  • Roadmap review finished 29th Feb 2024
  • refinement phase will start the next days
  • different open meetings can now be linked directly

Open Discussions

  • n/a

Security Office Hour 2024-02-29

Consortia Security Team Member

Security Office Hour meeting minutes

Announcements

  • Security team approvals for most projects in scope of release 24.03 have been completed.
  • Upcoming changes for release 24.05 will focus on FOSS security tools, including
    • switch from Veracode to CodeQL for SAST,
    • switch from Gitguardian to gitleaks for secrets scanning,
    • DAST will not be part of the upcoming TRG until further notice.
  • DAST was removed from TRG due to issues with authenticated scans and SARIF report as scanning alerts in repository security section.

Open Discussions

  • An overarching issue for tracking the tool shifts was discussed, as it is necessary for proper planning by teams.
    • Teams need to estimate efforts to adjust Github workflows
  • The PR for the new Security TRG was discussed, which includes a new requirement of remediation of findings with medium severity, but not for the 25.05 release.
    • Concerns were raised about the need for additional planned team resources for triaging these issues, and it was suggested that the TRG should be finalized and teams made aware.
  • What are best-practices for scheduling security tools Action workflows, with every PR or another frequency?
    • The TRG claims at least once, this is mandatory baseline for all.
    • Best practice is more frequently, recommendations differ per tool (e.g. secret scanning for every PR, dependency scan on a weekly basis).
    • The trigger will be on push + on pull + scheduled - frequency depends on repositories activity, so the team has to decide.
    • Best practice recommendations will be published in the sig-security repository.

Community Office Hour 2024-02-23

Sebastian Bezold
Consortia System Team Member

Office Hour meeting minutes

System team

  • Quality Gate Reviews in progress. Please keep an eye on your issues

Security team

  • New "Read only filesystem" TRG will be introduced to the "Container" category
  • New "Dependabot" TRG will be worked on via PR #659 and moved to the security section afterwards
  • With Release 24.05, Veracode will no longer be part of the QGate. We move to CodeQL. Do necessary migration early on, if possible

FOSS

Open planning / community

  • n/a

Open Discussions

  • Automated email about upgrades to Kubernetes and PostgreSQL version: What does it mean?
    • See it as a discussion starter and reminder
    • Potentially, the committer group can use that as a trigger for alignment on these two crucial topics
  • Is there a publicly available test installation of a dataspace build from Tractus-X components
    • No. Tractus-X is not maintaining any persistent installations
    • There are tutorials available on how to set this up yourself
    • MXD tutorial
    • E2E adopter journey
  • Is there a possibility to enable contributors ot edit other contributors issue descriptions
    • No. This is only possible with write permissions
    • Write permissions are only granted to the committer role

Community Office Hour 2024-02-16

Sebastian Bezold
Consortia System Team Member

Office Hour meeting minutes

System team

  • Still looking for volunteers to work on QG reviews together with the system team
    • Goal is to spread knowledge on how TRGs are checked
    • Especially interesting for committers, that already know they will stay post consortia
  • Preparing an open description on our release process. Feel free to comment any suggestion or important topics, you think should be covered on this draft
  • Markdown linting will again be enabled for KITs. Findings will be collected as issue per KIT
  • OpenAPI plugin for docusaurus will be removed
    • OpenAPI definitions will be pushed to SwaggerHub. User credentials available as org secrets
    • Ongoing discussions: Some definitions might be published through standard and therefore out of eclipse-tractusx

Security team

  • New TRG suggestion PR: eclipse-tractusx/eclipse-tractusx.github.io#681
  • Reminder: please focus on eclipse-tractusx instead of catenax-ng
  • Please reach out to the security team, as soon as the security scans for QG checks are ready for QG review

FOSS

Open planning / community