Skip to content
This repository has been archived by the owner on Feb 15, 2024. It is now read-only.

Quality, security and legal reporting/notifications #33

Closed
1 of 9 tasks
mcleo-d opened this issue Jan 16, 2020 · 2 comments
Closed
1 of 9 tasks

Quality, security and legal reporting/notifications #33

mcleo-d opened this issue Jan 16, 2020 · 2 comments
Labels
epic An ODP Epic feature writing Grooming and feature writing needed lfx prio-low Low priority
Milestone

Comments

@mcleo-d
Copy link
Member

mcleo-d commented Jan 16, 2020

Related to #31

Acceptance criteria:

  • As a visitor, I want to see all security/legal/quality in a public GitHub Project
  • As a FINOS Project Team member, I want to be able to get notified about security/legal/quality issues

Tasks:

Dependencies:

This story depends on the following ones:

Implementation

As we try to enforce GitOps as paradigm to bring continuous quality, security and legal compliance on across all our repositories, also reporting and notifications should align.

For example, in order to report on security, it is already possible to get the raw data from https://api.github.com/search/issues?q=org:finos%20label:%22security%20vulnerability%22

Using JQ, it is possible to export the data in any format.

@mcleo-d mcleo-d added atomic An atomic story feature writing Grooming and feature writing needed labels Jan 16, 2020
@mcleo-d mcleo-d added this to To do in Open Developer Platform Project Kanban via automation Jan 18, 2020
@maoo maoo removed the feature writing Grooming and feature writing needed label Jan 21, 2020
@maoo maoo changed the title FINOS PMCs are notified about project specific overrides Quality, security and legal reporting/notifications Jan 21, 2020
@maoo maoo added the prio-low Low priority label Mar 11, 2020
@maoo maoo added this to the Q3 2020 milestone Mar 28, 2020
@mcleo-d mcleo-d added epic An ODP Epic and removed atomic An atomic story labels Apr 3, 2020
@maoo
Copy link
Member

maoo commented Apr 3, 2020

As soon as finos/metadata-tool#60 is merged, the (FINOS internal) Metadata Tool nightly run will also report all repositories having issues labeled with security vulnerability and quality checks, allowing to have reporting abilities across security and quality aspects of our hosted code.

@maoo maoo added the feature writing Grooming and feature writing needed label Apr 20, 2020
@maoo
Copy link
Member

maoo commented Dec 11, 2020

Given the introduction of LFX (specifically, Insights and Vulnerability Detection) in our infrastructure, we are going to rely on those collaboration tools.

Closing issue and marking it with LFX label.

@maoo maoo closed this as completed Dec 11, 2020
Open Developer Platform Project Kanban automation moved this from To do to Done Dec 11, 2020
@maoo maoo added the lfx label Dec 11, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
epic An ODP Epic feature writing Grooming and feature writing needed lfx prio-low Low priority
Projects
No open projects
Development

No branches or pull requests

2 participants