Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

QG 4 checks (Release 24.05) #122

Closed
37 tasks done
almadigabor opened this issue May 15, 2024 · 8 comments
Closed
37 tasks done

QG 4 checks (Release 24.05) #122

almadigabor opened this issue May 15, 2024 · 8 comments
Assignees
Labels
documentation Improvements or additions to documentation

Comments

@almadigabor
Copy link
Contributor

almadigabor commented May 15, 2024

QG checks

Please keep this issue open until QG is concluded and will be managed by the Issue Creator!
We will inform you about finding and proposals in separated issues, this issue here is for the Overview of the Checks!

Please keep this issue open until QG is concluded!

Product Owner: @drcgjung
Dev SPOC: @drcgjung
Helm Chart Version: 1.12.19
App Version: 1.12.19

Release Managemnet Reference Issue:

Check of Tractus-X Release Guidelines

TRG 1 Documentation

  • TRG 1.01 appropriate README.md
  • TRG 1.02 appropriate install instructions either INSTALL.md or in README.md
  • TRG 1.03 appropriate CHANGELOG.md
  • TRG 1.04 editable static files

TRG 2 Git

TRG 3 Kubernetes

  • TRG 3.02 persistent volume and persistent volume claim is used when needed

TRG 4 Container

TRG 5 Helm

  • TRG 5.01 Helm chart requirements
  • TRG 5.02 Helm chart location in /charts directory and correct structure
  • TRG 5.03 proper version strategy
  • TRG 5.04 CPU / MEM resource requests and limits and are properly set
  • TRG 5.06 Application must be configurable through the Helm chart
  • TRG 5.07 Dependencies are present and properly configured in the Chart.yaml
  • TRG 5.08 Product has a single deployable helm chart that contains all components
  • TRG 5.09 Helm Test running properly
  • TRG 5.10 Products need to support 3 versions at a time
  • TRG 5.11 Upgradeability

TRG 6 Released Helm Chart

TRG 7 Open Source Governance

  • TRG 7.01 Legal Documentation
  • TRG 7.02 License and copyright header
  • TRG 7.03 IP checks for project content
  • TRG 7.04 IP checks for 3rd party content
  • TRG 7.05 Legal information for distributions
  • TRG 7.06 Legal information for end user content
  • TRG 7.07 Legal notice for documentation
  • TRG 7.08 Legal notice for KIT documentation

TRG 8 Security

Hints

Information Sharing

@almadigabor almadigabor added the documentation Improvements or additions to documentation label May 15, 2024
@almadigabor almadigabor self-assigned this May 15, 2024
@almadigabor
Copy link
Contributor Author

Hi all, before I start I need the following info:

Product Owner:
Dev SPOC:
Helm Chart Version:
App Version:

Also I will need a volunteer committer who does the checks alongside with me. Can you find me someone? Thanks!

@almadigabor
Copy link
Contributor Author

Version I'm checking: 1.12.19

@almadigabor
Copy link
Contributor Author

I'm done with the first round of checks. There is one issues open regarding critical security findings in the knowledge-agents repository by CodeQL. #128

@RolaH1t
Copy link

RolaH1t commented May 27, 2024

@drcgjung & @almadigabor do we expect a resolution on this one today?

@drcgjung
Copy link
Contributor

@drcgjung & @almadigabor do we expect a resolution on this one today?

here eclipse-tractusx/knowledge-agents-edc#196
and here #131

Best,
CGJ

@RolaH1t
Copy link

RolaH1t commented May 27, 2024

cool!
so please mark #122(#122) completed and update #641(eclipse-tractusx/sig-release#641) so QG can be fully approved

@RoKrish14
Copy link
Contributor

CodeQl: I approve the findings as FP. The security checks is approved.

@almadigabor
Copy link
Contributor Author

As the security findings were false positives as they've already been fixed, the last check is also marked. I approve the QG with the following versions:

App version: 1.12.19
Chart version: 1.12.19

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
documentation Improvements or additions to documentation
Projects
Archived in project
Development

No branches or pull requests

4 participants