Ensure all Jenkins jobs are working fine for the SO repositories taht are part of Jakarta release,
Update the vulnerable direct dependencies in their code base following the recommendations of SECCOM documented in https://wiki.onap.org/display/SV/Jakarta+SO
Identify resource or technical constraints to SECCOM by (M2).
Submit a LF Ticket for access to the Security Vulnerabilities space (if needed).
Execute packages upgrades accordingly.
Update statuses in the restricted Wiki (link above).
For the agreed resource or technical constraints provide waiver status with declaration on when it is planned to be solved.
- relates to
REQ-1066 PACKAGES UPGRADES IN DIRECT DEPENDENCIES FOR JAKARTA
- To Do
|127612,1||Dependency version upgrade ch.qos.logback:logback-core: 1.2.3 to 1.2.10||master||so||Status: MERGED||+2||+1|