Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

R24.05 Portal Assets - Release Checks #315

Closed
37 tasks done
fabiodmota opened this issue May 14, 2024 · 3 comments
Closed
37 tasks done

R24.05 Portal Assets - Release Checks #315

fabiodmota opened this issue May 14, 2024 · 3 comments
Assignees
Labels
documentation Improvements or additions to documentation

Comments

@fabiodmota
Copy link

fabiodmota commented May 14, 2024

QG checks

Please keep this issue open until QG is concluded and will be managed by the Issue Creator!
We will inform you about finding and proposals in separated issues, this issue here is for the Overview of the Checks!

Please keep this issue open until QG is concluded!

Product Owner: @jjeroch
Dev SPOC: @evegufy
Helm Chart Version: Portal: 2.0.0 (RC7)
App Version: Portal: 2.0.0 (RC1)

Release Management Reference Issue: eclipse-tractusx/sig-release#671

Check of Tractus-X Release Guidelines

TRG 1 Documentation

  • TRG 1.01 appropriate README.md
  • TRG 1.02 appropriate install instructions either INSTALL.md or in README.md
  • TRG 1.03 appropriate CHANGELOG.md
  • TRG 1.04 editable static files

TRG 2 Git

TRG 3 Kubernetes

  • TRG 3.02 persistent volume and persistent volume claim is used when needed

TRG 4 Container

TRG 5 Helm

  • TRG 5.01 Helm chart requirements
  • TRG 5.02 Helm chart location in /charts directory and correct structure
  • TRG 5.03 proper version strategy
  • TRG 5.04 CPU / MEM resource requests and limits and are properly set
  • TRG 5.06 Application must be configurable through the Helm chart
  • TRG 5.07 Dependencies are present and properly configured in the Chart.yaml
  • TRG 5.08 Product has a single deployable helm chart that contains all components
  • TRG 5.09 Helm Test running properly
  • TRG 5.10 Products need to support 3 versions at a time
  • TRG 5.11 Upgradeability

TRG 6 Released Helm Chart

TRG 7 Open Source Governance

  • TRG 7.01 Legal Documentation
  • TRG 7.02 License and copyright header
  • TRG 7.03 IP checks for project content
  • TRG 7.04 IP checks for 3rd party content
  • TRG 7.05 Legal information for distributions
  • TRG 7.06 Legal information for end user content
  • TRG 7.07 Legal notice for documentation
  • TRG 7.08 Legal notice for KIT documentation

TRG 8 Security

  • TRG 8.01 Mitigate high and above findings in CodeQL
  • TRG 8.02 Mitigate high and above findings in KICS
  • TRG 8.03 Mitigate high and above findings in GitGuardian
  • TRG 8.04 Mitigate high and above findings in Trivy

Hints

Information Sharing

@fabiodmota fabiodmota added the documentation Improvements or additions to documentation label May 14, 2024
@fabiodmota
Copy link
Author

QG issue from TRG 1 to TRG7 checks done

@evegufy
Copy link
Contributor

evegufy commented May 28, 2024

@RoKrish14 could you please perform the security checks?

@RoKrish14
Copy link

Done and approved 👍

@evegufy evegufy closed this as completed May 28, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
documentation Improvements or additions to documentation
Projects
None yet
Development

No branches or pull requests

3 participants