[onap-tsc] VF-C PTL Elections Results

2020-06-17 Thread Yan Yang
Dear TSC,

 

The VF-C team has held the elections for PTL posting, Yuanhong Deng was the
only nomination and has been elected to serve as VF-C PTL for next 12
months.

Here are the voting results:
https://civs.cs.cornell.edu/cgi-bin/results.pl?id=E_bf5b83b074b93ed5 

Wiki is updated as well:
https://wiki.onap.org/display/DW/Voting+Results+History

 

 

 

Best Regards,

Yan Yang


-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.

View/Reply Online (#6559): https://lists.onap.org/g/onap-tsc/message/6559
Mute This Topic: https://lists.onap.org/mt/74933574/21656
Group Owner: onap-tsc+ow...@lists.onap.org
Unsubscribe: https://lists.onap.org/g/onap-tsc/leave/2743226/1412191262/xyzzy  
[arch...@mail-archive.com]
-=-=-=-=-=-=-=-=-=-=-=-



[onap-tsc] Stepping down as VF-C PTL role

2020-06-05 Thread Yan Yang
Dear TSC,

 

Due to a shift in my role and responsibilities within the company, I want to
let you know that I'm stepping down as the PTL of the VF-C project effective
today (June 5, 2020).But I would be delighted to help with any last minute
activity that comes up for the sign off of ONAP Frankfurt release. 

 

Thanks again for giving me the opportunity to serve as the PTL for VF-C
projet in the past six releases and it is really a wonderful journey to work
with everyone in the community.

 

As required by the process, I will follow the official ONAP process for the
next VF-C PTL elections as soon as I can.

 

 

 

Thanks and Regards,

Yan Yang


-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.

View/Reply Online (#6483): https://lists.onap.org/g/onap-tsc/message/6483
Mute This Topic: https://lists.onap.org/mt/74687908/21656
Group Owner: onap-tsc+ow...@lists.onap.org
Unsubscribe: https://lists.onap.org/g/onap-tsc/leave/2743226/1412191262/xyzzy  
[arch...@mail-archive.com]
-=-=-=-=-=-=-=-=-=-=-=-



[onap-tsc] 答复: [onap-ptl] [ONAP] [Frankfurt] Integration status for RC2

2020-06-01 Thread Yan Yang
Hi Morgan,

 

I have confirmed the release version of vfc artifacts and updated the
VFC-1665 status yesterday morning (Beijing time) and I also clarified the
latest status  at the PTL meeting yesterday. Please double check. Thanks.

 

BTW, we have upgrade VFC components three times  from M4 to RC1. And almost
all issue we have fixed during vCPE integration testing, From RC1, there is
no more changes and bug fixed.

 

 

BR,

Yan

发件人: onap-...@lists.onap.org [mailto:onap-...@lists.onap.org] 代表 Morgan
Richomme via lists.onap.org
发送时间: 2020年6月1日 18:30
收件人: David McBride; Lefevre, Catherine; onap-...@lists.onap.org
抄送: onap-tsc@lists.onap.org; Krzysztof Opasiak; ZWARICO, AMY; 'Pawel
Pawlak'; David Perez Caparros
主题: [onap-ptl] [ONAP] [Frankfurt] Integration status for RC2

 

Hi

 

I will not be able to attend this afternoon (Public holiday in Europe).

I updated the status for the PTL meeting

 

1) Do we have all our RC2 dockers?

*

the Readiness board is up to date:
https://wiki.onap.org/display/DW/Frankfurt+Readiness+dashboard

 

RC2 dockers are missing for some projects

They have been merged in Master Gate and are still in Frankfurt Gate for
OOF, SDC and AAI

They are still in Master Gate for AAF and SO 

 

I need also some clarification for SDNC and CDS 

for CDS:  there are some patches for frankfurt in CCSDK gerrit
(https://gerrit.onap.org/r/c/ccsdk/features/+/108581) but I did not find any
corresponding OOM patches yet

for SDNC: As the docker versions of the master branches are different than
the ones of the frankfurt branch, I just need to be sure that the versions
in Master are for Guilin and the ones in Frankfurt are the right ones.

Otherwise the integration in OOM is missing.

 

Finally I did not get any feedback from VFC.

I imagine that the versions are the right ones - no changes since M4..and
possibly no lots of changes from El Alto.

But I need a confirmation to close the JIRA.

 

I updated the follow up pod by pod:
https://docs.google.com/spreadsheets/d/1t3GNRtabdkVxG4ZAxqBJ-X7OO-Zv6xRwd8Kr
R52V9zU/edit?usp=sharing

 

the RC1 1/06 (=RC2 candidate) column = results of the Frankfurt Daily run
executed today:
https://gating-results.onap.eu/results/onap_daily_pod4_frankfurt-574930638-0
6-01-2020_02-06/

the RC2 target includes the versions currently in gate in Frankfurt or in
Master (announced for Frankfurt in patch), the ?? corresponds to the open
question (tracked in the JIRA)

the Master column = results of the Master Daily branch executed today:
https://gating-results.onap.eu/results/onap_daily_pod4_master-575064753-06-0
1-2020_06-06/

 

Considering the RC2 target, column

green => we have the dockers, we are ready

orange => the dockers in OOM frankfurt are not the ones we expected

 

so from a Readiness point of view it is a NOGO.

 

2) Use cases

**

 

30 on 31 use cases had been completed in RC1.

last use case was about 75%.

Wait for RC2 dockers for regression tests (but need the RC2 dockers for
that)

 

Please also note that the 72h stability test was OK

 

3) CI

**

results are not bad (bad results on the 28th seem to be due to hardware
transient issue)

we should now be able to get a 100% on smoke tests (current results in daily
Master)

 

I summarized the CI test results in the following graphs

Note that the threshold change for smoke tests as we introduced new use
cases in CI during the RC0-RC2 period, some issues have been found on fixed
that is why the target is now 100%

 

错误!未指定文件名。

 

 

Conclusions

*

 

NOGO

 

Action points for the PTL

- finalize the merge for the OOF, SDC, AAI

- finalize Master merge then Frankfurt merge for AAF and SO

- Clarify SDNC, CCSK, VFC

 

/Morgan


_
 
Ce message et ses pieces jointes peuvent contenir des informations
confidentielles ou privilegiees et ne doivent donc
pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu
ce message par erreur, veuillez le signaler
a l'expediteur et le detruire ainsi que les pieces jointes. Les messages
electroniques etant susceptibles d'alteration,
Orange decline toute responsabilite si ce message a ete altere, deforme ou
falsifie. Merci.
 
This message and its attachments may contain confidential or privileged
information that may be protected by law;
they should not be distributed, used or copied without authorisation.
If you have received this email in error, please notify the sender and
delete this message and its attachments.
As emails may be altered, Orange is not liable for messages that have been
modified, changed or falsified.
Thank you.




-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.

View/Reply Online (#6459): https://lists.onap.org/g/onap-tsc/message/6459
Mute This Topic: https://lists.onap.org/mt/74618516/21656
Group Owner: 

[onap-tsc] ONAP VF-C PTL 2019 Election Result

2019-07-30 Thread Yan Yang
Dear Team,

 

It is my pleasure to announce that I have the honor of serving as VF-C
Project PTL for another year.

 

Thank you for all your support and  I look forward to continuing to work
with you all.

 

The voting result :
https://civs.cs.cornell.edu/cgi-bin/results.pl?id=E_403d1ddfd828550d  , the
wiki page will be updated accordingly.  Thanks.

 

 

Best Regards,

Yan

发件人: Yan Yang [mailto:yangya...@chinamobile.com] 
发送时间: 2019年7月25日 18:00
收件人: 'anatoly.andria...@nokia.com'; 'fu.jin...@zte.com.cn'; 'Gaoweitao
(Victor, Cloudify Network OSDT)'; 'hanya...@raisecom.com'; 'luxin (F)';
'zhang.maope...@zte.com.cn'; 'kanagaraj.manic...@huawei.com';
'ying.yunl...@zte.com.cn'; 'yog.vashis...@ril.com'; 'Lingli Deng'; 'nagesha.
subrama...@nokia.com'; 'Xinhui Li'; 'wangguirong'; 'adityakar@ril.com';
'don...@raisecom.com'; 'Nemeth, Denes (Nokia - HU/Budapest)'; 'Huang,
Haibin'; 'lai...@zte.com.cn'; 'bharath.thiruveed...@verizon.com'; 'Ying,
Ruoyu'; 'onap-tsc@lists.onap.org'
主题: 答复: Call for nominations of VF-C PTL 2019-2020

 

Dear VF-C committers,

I would like to nominate myself to continue as PTL for VF-C project.

 

I have served as the VF-C PTL for four releases. As the PTL of VF-C, I
worked with excellent VF-C team to release four releases of ONAP. 

My intention is to continue working as the PTL for the VF-C project  and to
do my best to continue to contribute to ONAP.

 

 

Best Regards,

Yan Yang 

发件人: Yan Yang [mailto:yangya...@chinamobile.com] 
发送时间: 2019年7月24日 9:26
收件人: 'anatoly.andria...@nokia.com'; 'fu.jin...@zte.com.cn'; 'Gaoweitao
(Victor, Cloudify Network OSDT)'; 'hanya...@raisecom.com'; 'luxin (F)';
'zhang.maope...@zte.com.cn'; 'kanagaraj.manic...@huawei.com';
'ying.yunl...@zte.com.cn'; 'yog.vashis...@ril.com'; 'Lingli Deng'; 'nagesha.
subrama...@nokia.com'; 'Xinhui Li'; 'wangguirong'; 'adityakar@ril.com';
'don...@raisecom.com'; 'Nemeth, Denes (Nokia - HU/Budapest)'; 'Huang,
Haibin'; 'lai...@zte.com.cn'; 'bharath.thiruveed...@verizon.com'; 'Ying,
Ruoyu'; 'onap-tsc@lists.onap.org'
主题: Call for nominations of VF-C PTL 2019-2020

 

Hello VF-C committers,

 

As required by ONAP process
https://wiki.onap.org/display/DW/Annual+Community+Elections#AnnualCommunityE
lections-PTLElections
<https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.onap.org_display_
DW_Annual-2BCommunity-2BElections-23AnnualCommunityElections-2DPTLElections&
d=DwMGaQ=LFYZ-o9_HUMeMTSQicvjIg=WrNqy1qTY6qs8trIiLe-U2OvGp0SXnE4nO3a-LJ-
q_w=vPtAEEdY3Cj3YkEYKXUS0l74u93a0jGJm6IQ9eqzeZc=jHY3KX62I2qEPxb3UR-YPV8I
-yZEui6_hmNlq7SfpiM=> , the annual ONAP PTL elections have started. 

 

Please reply to this email if you would like to self-nominate.  Nominations
are due by July 26 at 5:00 PM Beijing time.

 

Regards,

Yan Yang

 


-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.

View/Reply Online (#5302): https://lists.onap.org/g/onap-tsc/message/5302
Mute This Topic: https://lists.onap.org/mt/32652332/21656
Group Owner: onap-tsc+ow...@lists.onap.org
Unsubscribe: https://lists.onap.org/g/onap-tsc/leave/2743226/1412191262/xyzzy  
[arch...@mail-archive.com]
-=-=-=-=-=-=-=-=-=-=-=-



[onap-tsc] 答复: Call for nominations of VF-C PTL 2019-2020

2019-07-25 Thread Yan Yang
Dear VF-C committers,

I would like to nominate myself to continue as PTL for VF-C project.

 

I have served as the VF-C PTL for four releases. As the PTL of VF-C, I
worked with excellent VF-C team to release four releases of ONAP. 

My intention is to continue working as the PTL for the VF-C project  and to
do my best to continue to contribute to ONAP.

 

 

Best Regards,

Yan Yang 

发件人: Yan Yang [mailto:yangya...@chinamobile.com] 
发送时间: 2019年7月24日 9:26
收件人: 'anatoly.andria...@nokia.com'; 'fu.jin...@zte.com.cn'; 'Gaoweitao
(Victor, Cloudify Network OSDT)'; 'hanya...@raisecom.com'; 'luxin (F)';
'zhang.maope...@zte.com.cn'; 'kanagaraj.manic...@huawei.com';
'ying.yunl...@zte.com.cn'; 'yog.vashis...@ril.com'; 'Lingli Deng'; 'nagesha.
subrama...@nokia.com'; 'Xinhui Li'; 'wangguirong'; 'adityakar@ril.com';
'don...@raisecom.com'; 'Nemeth, Denes (Nokia - HU/Budapest)'; 'Huang,
Haibin'; 'lai...@zte.com.cn'; 'bharath.thiruveed...@verizon.com'; 'Ying,
Ruoyu'; 'onap-tsc@lists.onap.org'
主题: Call for nominations of VF-C PTL 2019-2020

 

Hello VF-C committers,

 

As required by ONAP process
https://wiki.onap.org/display/DW/Annual+Community+Elections#AnnualCommunityE
lections-PTLElections
<https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.onap.org_display_
DW_Annual-2BCommunity-2BElections-23AnnualCommunityElections-2DPTLElections&
d=DwMGaQ=LFYZ-o9_HUMeMTSQicvjIg=WrNqy1qTY6qs8trIiLe-U2OvGp0SXnE4nO3a-LJ-
q_w=vPtAEEdY3Cj3YkEYKXUS0l74u93a0jGJm6IQ9eqzeZc=jHY3KX62I2qEPxb3UR-YPV8I
-yZEui6_hmNlq7SfpiM=> , the annual ONAP PTL elections have started. 

 

Please reply to this email if you would like to self-nominate.  Nominations
are due by July 26 at 5:00 PM Beijing time.

 

Regards,

Yan Yang

 


-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.

View/Reply Online (#5288): https://lists.onap.org/g/onap-tsc/message/5288
Mute This Topic: https://lists.onap.org/mt/32596569/21656
Group Owner: onap-tsc+ow...@lists.onap.org
Unsubscribe: https://lists.onap.org/g/onap-tsc/leave/2743226/1412191262/xyzzy  
[arch...@mail-archive.com]
-=-=-=-=-=-=-=-=-=-=-=-



[onap-tsc] Call for nominations of VF-C PTL 2019-2020

2019-07-23 Thread Yan Yang
Hello VF-C committers,

 

As required by ONAP process
https://wiki.onap.org/display/DW/Annual+Community+Elections#AnnualCommunityE
lections-PTLElections
<https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.onap.org_display_
DW_Annual-2BCommunity-2BElections-23AnnualCommunityElections-2DPTLElections&
d=DwMGaQ=LFYZ-o9_HUMeMTSQicvjIg=WrNqy1qTY6qs8trIiLe-U2OvGp0SXnE4nO3a-LJ-
q_w=vPtAEEdY3Cj3YkEYKXUS0l74u93a0jGJm6IQ9eqzeZc=jHY3KX62I2qEPxb3UR-YPV8I
-yZEui6_hmNlq7SfpiM=> , the annual ONAP PTL elections have started. 

 

Please reply to this email if you would like to self-nominate.  Nominations
are due by July 26 at 5:00 PM Beijing time.

 

Regards,

Yan Yang

 


-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.

View/Reply Online (#5278): https://lists.onap.org/g/onap-tsc/message/5278
Mute This Topic: https://lists.onap.org/mt/32581052/21656
Group Owner: onap-tsc+ow...@lists.onap.org
Unsubscribe: https://lists.onap.org/g/onap-tsc/leave/2743226/1412191262/xyzzy  
[arch...@mail-archive.com]
-=-=-=-=-=-=-=-=-=-=-=-



[onap-tsc] Dublin release participation - VF-C

2018-12-02 Thread Yan Yang
Dear TSC,

 

This is to inform you that the VF-C project intends to participate in the
Dublin release. 

 

 

Best Regards,

Yan Yang

VF-C PTL


-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.

View/Reply Online (#4217): https://lists.onap.org/g/onap-tsc/message/4217
Mute This Topic: https://lists.onap.org/mt/28566956/21656
Group Owner: onap-tsc+ow...@lists.onap.org
Unsubscribe: https://lists.onap.org/g/onap-tsc/leave/2743226/1412191262/xyzzy  
[arch...@mail-archive.com]
-=-=-=-=-=-=-=-=-=-=-=-



答复: [onap-tsc] Soliciting interest for ONAP internship projects

2018-10-17 Thread Yan Yang
HI  Lingli,

 

Following is one proposal  for VF-C Project.

Description: Supporting VNF Initial configuration in VF-C GVNFM

Additional Information: Implement VNF Initial configuration function via SSH in 
VF-C which includes SSH remote connection via username/password, or auth key, 
SSH execution and parse SSH result. 

Study and implement (if time allows) more init configuration method to VNF.

Desirable Skills: Python, SSH, Django

Expected Outcome: Providing the VNF Initial configuration function via SSH in 
VF-C GVNFM

Difficulty: Medium

Desired project timeline/completion date: 2019/03

Mentor(s) & contact info:

Name: Yan Yang

Tel: 86-15210838572

E-mail: yangya...@chinamobile.com

 

Best Regards,

Yan

发件人: onap-tsc@lists.onap.org [mailto:onap-tsc@lists.onap.org] 代表 Lingli Deng
发送时间: 2018年10月12日 15:06
收件人: onap-tsc
主题: [onap-tsc] Soliciting interest for ONAP internship projects

 

Hi all,

 

Per the discussion during the TSC all earlier today, for the sake of getting a 
rough sense for budgeting internship program for ONAP next year, I am writing 
to solicit interest for related internship project proposals.

If you are interested in proposing an internship project for augmenting ONAP 
and/or willing to help in mentoring it on execution (including defining the 
project scope, developing the implmentation plan for the project, and 
recruting, supervising and reviewing the intern for its execution), please 
reply with your ideas by filling the information in the following template by 
next Monday.

(More description for LFN internship program would be found here: 
https://wiki.lfnetworking.org/display/LN/LF+Networking+Internships#LFNetworkingInternships-ProposingaProject)

 

Description:

Additional Information:

 

Desirable Skills:

 

Expected Outcome:

 

Difficulty:

Hihg/Medium/Low

Desired project timeline/completion date:

 

Mentor(s) & contact info:

Thanks,

Lingli/邓灵莉

中国移动通信研究院

denglin...@chinamobile.com

 




-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.

View/Reply Online (#3939): https://lists.onap.org/g/onap-tsc/message/3939
Mute This Topic: https://lists.onap.org/mt/27400049/21656
Group Owner: onap-tsc+ow...@lists.onap.org
Unsubscribe: https://lists.onap.org/g/onap-tsc/leave/2743226/1412191262/xyzzy  
[arch...@mail-archive.com]
-=-=-=-=-=-=-=-=-=-=-=-



[onap-tsc] [VFC] PTL Election for VF-C Project - self nomination

2018-07-03 Thread Yan Yang
Hi all VF-C committers,

 

As mandated by ONAP process, PTL elections must be held at least once a
year. 

You can read more details here:
https://wiki.onap.org/display/DW/Annual+Community+Elections 

 

 

My self-nomination:

I would like to nominate myself as Project Technical Lead (PTL) for the VF-C
project. I have served as the VF-C PTL for the past year. As the PTL of
VF-C, I worked with excellent VF-C team to release the first two releases of
ONAP. 

My intention is to continue working as the PTL for the VF-C project at least
for this year until Casablanca is delivered.

 

 

I invite you to submit your self-nomination if you are interested in this
position.

You have 2 days to submit your self-nomination from receipt of this email.

 

Dates:

Self-nomination will close at Friday, 6 July 2018 @ 9:00am Beijing time.

Voting will be open for 3 days after that point and close Monday 9 July 2018
@ 9:00am Beijing time.

New PTL will be announced on 10 July 2018.

 

Best Regards,

Yan

 

 


-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.

View/Reply Online (#3270): https://lists.onap.org/g/ONAP-TSC/message/3270
Mute This Topic: https://lists.onap.org/mt/23035611/21656
Group Owner: onap-tsc+ow...@lists.onap.org
Unsubscribe: https://lists.onap.org/g/ONAP-TSC/unsub  [arch...@mail-archive.com]
-=-=-=-=-=-=-=-=-=-=-=-



[onap-tsc] Casablanca release participation - VF-C

2018-06-07 Thread Yan Yang
Dear ONAP TSC,

 

This email is to inform you that the Virtual Function Controller project
(VF-C) intends to participate in the ONAP Casablanca release.

 

Thanks,

Yan Yang

VF-C PTL

 

___
ONAP-TSC mailing list
ONAP-TSC@lists.onap.org
https://lists.onap.org/mailman/listinfo/onap-tsc


[onap-tsc] 答复: ONAP Vulnerability Report - VF-C

2018-04-07 Thread Yan Yang
Have updated. 

 

Best Regards,

Yan

发件人: ZWARICO, AMY [mailto:az9...@att.com] 
发送时间: 2018年4月5日 2:41
收件人: Yan Yang
抄送: 'onap-tsc'; onap-sec...@lists.onap.org
主题: RE: ONAP Vulnerability Report - VF-C

 

Thank you for the information. Please update the vulnerability analysis in the 
wiki (https://wiki.onap.org/pages/viewpage.action?pageId=25437810) with this 
information.

Thank you, Amy

 

From: Yan Yang [mailto:yangya...@chinamobile.com] 
Sent: Tuesday, April 03, 2018 3:05 AM
To: ZWARICO, AMY <az9...@att.com>
Cc: 'onap-tsc' <onap-tsc@lists.onap.org>; onap-sec...@lists.onap.org
Subject: 答复: ONAP Vulnerability Report - VF-C

 

Hi Amy,

 

Please see my response to your question below

 

Best Regards,

Yan

发件人: ZWARICO, AMY [mailto:az9...@att.com] 
发送时间: 2018年4月1日 3:28
收件人: yangya...@chinamobile.com
抄送: onap-tsc; onap-sec...@lists.onap.org
主题: ONAP Vulnerability Report - VF-C

 

Hi Yan,

I was reviewing the Usecase-UI known vulnerability analysis – thank-you for 
providing that (https://wiki.onap.org/pages/viewpage.action?pageId=25437810 
<https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.onap.org_pages_viewpage.action-3FpageId-3D25437810=DwQFaQ=LFYZ-o9_HUMeMTSQicvjIg=PJ-KGa4esrIcYgd1dEzHLA=1PfZYnz3vSDutCZe8yAePcEtBgPWz7och1wpTVsM0vI=EGBXa4v3hSzTNof_2evGpMHcZNZTiUJa2FumIwlBsL8=>
 )

1.   Is VF-C using the vulnerable component(s) in commons-httpclient?

[Yan]VF-C code don’t use the readRawLine() method in commons-httpclient 
directly. We plan to replace this jar with Apache HttpComponents, but need some 
time to update the code and test. 

2.   Is VF-C using the vulnerable component(s) in jackson-mapper-asl?

   [Yan] We don’t use Jackson directly and don’t use 
createBeanDeserializer() function which has the vulnerability. We were unable 
to find any reference to this Vulnerability 

3.   Is VF-C using the vulnerable component(s) in xercesImpl?

   [Yan]  About the xercesImpl security issue, we have replaced it 
with new version and this issue have been solved.

 

Thanks so much,

Amy

 

​Amy Zwarico, LMTS

Chief Security Office / Enterprise Security Support / Cloud Security Services

AT Services

(205) 403-2241

 

"This e-mail and any files transmitted with it are the property of AT,  and 
are intended solely for the use of the individual or entity to whom this e-mail 
is addressed. If you are not one of the named recipient(s) or otherwise have 
reason to believe that you have received this message in error, please notify 
the sender and delete this message immediately from your electronic device. Any 
other use, retention, dissemination, forwarding, printing, or copying of this 
e-mail is strictly prohibited."

 

 

 

 

___
ONAP-TSC mailing list
ONAP-TSC@lists.onap.org
https://lists.onap.org/mailman/listinfo/onap-tsc


[onap-tsc] 答复: ONAP Vulnerability Report - VF-C

2018-04-03 Thread Yan Yang
Hi Amy,

 

Please see my response to your question below

 

Best Regards,

Yan

发件人: ZWARICO, AMY [mailto:az9...@att.com] 
发送时间: 2018年4月1日 3:28
收件人: yangya...@chinamobile.com
抄送: onap-tsc; onap-sec...@lists.onap.org
主题: ONAP Vulnerability Report - VF-C

 

Hi Yan,

I was reviewing the Usecase-UI known vulnerability analysis – thank-you for 
providing that (https://wiki.onap.org/pages/viewpage.action?pageId=25437810)

1.   Is VF-C using the vulnerable component(s) in commons-httpclient?

[Yan]VF-C code don’t use the readRawLine() method in commons-httpclient 
directly. We plan to replace this jar with Apache HttpComponents, but need some 
time to update the code and test. 

2.   Is VF-C using the vulnerable component(s) in jackson-mapper-asl?

   [Yan] We don’t use Jackson directly and don’t use 
createBeanDeserializer() function which has the vulnerability. We were unable 
to find any reference to this Vulnerability 

3.   Is VF-C using the vulnerable component(s) in xercesImpl?

   [Yan]  About the xercesImpl security issue, we have replaced it 
with new version and this issue have been solved.

 

Thanks so much,

Amy

 

​Amy Zwarico, LMTS

Chief Security Office / Enterprise Security Support / Cloud Security Services

AT Services

(205) 403-2241

 

"This e-mail and any files transmitted with it are the property of AT,  and 
are intended solely for the use of the individual or entity to whom this e-mail 
is addressed. If you are not one of the named recipient(s) or otherwise have 
reason to believe that you have received this message in error, please notify 
the sender and delete this message immediately from your electronic device. Any 
other use, retention, dissemination, forwarding, printing, or copying of this 
e-mail is strictly prohibited."

 

 

 

 

___
ONAP-TSC mailing list
ONAP-TSC@lists.onap.org
https://lists.onap.org/mailman/listinfo/onap-tsc