Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.


Topic Leader(s)

Topic Overview

Excerpt


Static scanning is regularly performed on LFN repositories. Unfortunately they only detect potential explicit issues. Most of the projects include their code within a broader context which includes lots of possible dependencies. Hosting and redistributing docker containers have consequences in legal issues. We must have a better control of what we are distributing. Dynamic scanning is then needed. Some tools are available and a feedback shall be given as soon as possible as close as possible in the  build chain. Alexander Mazuruk worked on a PoC in ONAP invoving tern+dockviz, the goal would be to include such verification on any docker build jobs


Slides & Recording

View file
nameLFN-vEvent-Tern_6.pdf
height150

View file
nameDynamic License Scanning.mp4
height150

Minutes




Action Items


  •