Hi,

Alexander developed a test to perform a Tern scanning on ONAP cluster.
You can see the last results here:
https://logs.onap.org/onap-integration/weekly/onap_weekly_pod4_master/2021-04/19_18-36/security/tern/index.html
He is currently finalizing the integration in CI (weekly chains): tern test 
under security section

you need to have a json extension to view the report properly.
In the first part you have a summary of the licenses scanned in the pods
in the detailed section, you can have details > images > <id> >image > layers > 
<layer id> packages > <package id>

See the presentation done during the DDF on this topic: 
https://wiki.lfnetworking.org/display/LN/2021-02-01+-+Plenary%3A+Dynamic+License+Scanning

There is already some ongoing discussions with AAI 
(https://jira.onap.org/browse/AAI-3194) or OOF 
(https://jira.onap.org/browse/OPTFRA-853)
We may plan a discussion during the PTL meeting and see how we can help projects

If you are inheriting "rich" images (jetty/ubuntu/) do not be surprised to see 
lots of GPL references...
The recommendation is to move to integration baseline image.
The integration java baseline is GPL free as it is a minimal image including 
the Java version in an alpine docker (versions recommended by the SECCOM).

/Morgan

_________________________________________________________________________________________________________________________

Ce message et ses pieces jointes peuvent contenir des informations 
confidentielles ou privilegiees et ne doivent donc
pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce 
message par erreur, veuillez le signaler
a l'expediteur et le detruire ainsi que les pieces jointes. Les messages 
electroniques etant susceptibles d'alteration,
Orange decline toute responsabilite si ce message a ete altere, deforme ou 
falsifie. Merci.

This message and its attachments may contain confidential or privileged 
information that may be protected by law;
they should not be distributed, used or copied without authorisation.
If you have received this email in error, please notify the sender and delete 
this message and its attachments.
As emails may be altered, Orange is not liable for messages that have been 
modified, changed or falsified.
Thank you.



-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#23152): https://lists.onap.org/g/onap-discuss/message/23152
Mute This Topic: https://lists.onap.org/mt/82288085/21656
Group Owner: onap-discuss+ow...@lists.onap.org
Unsubscribe: https://lists.onap.org/g/onap-discuss/unsub 
[arch...@mail-archive.com]
-=-=-=-=-=-=-=-=-=-=-=-


Reply via email to