Skip to main content

Community Office Hour 2024-08-30

Tractus-X Committer

Office Hour meeting minutes

Infrastructure

  • @ds-hzimmer will continue to report from the monthly infrastructure updates that are to happen every month's last sunday.
    • product teams will have to check their deployments after that

Security team

  • Trufflehog has now officially replaced GitGuardian as secret-scanning tool for Eclipse Tractus-X. This is encoded by TRG8.03
  • @ds-hzimmer reports about the sporadic use of the current sonarcloud instance for Eclipse Tractus-X. There's no TRG for it. It's unclear what additional benefit it will bring to those tools that are backed up with TRGs (Trufflehog, trivy, codeql).

Q&A

  • @tom-rm-meyer-ISST reports issues with the tls provider which will be checked with the infrastructure team.

Community Office Hour 2024-08-02

Tom Meyer
PURIS Architect, Eclipse Committer

Office Hour meeting minutes

Infrastructure

  • Discussion on catenax-ng
    • @matbmoser: please cross-check your own repository, if you reference it!
    • @lgblaumeiser: we noticed that the R24.03 MIW needs catenax-ng resources. It temporarily stays up. (see issue)
  • Consortia teams are gone. Thanks, it was a pleasure!

Security team

  • @matbmoser: Please do check for your security issues on the tab. High and critical issues need to be fixed. We should check this on high level / project level regularly in this meeting
  • @tom-rm-meyer-ISST: For Truffle Hog, make sure that the workflow runs before merging. (see e.g.)

FOSS

  • @AngelikaWittek is gone. Thanks for your work!

Open planning / community

  • @stephanbcbauer:
    • Refinement Phase went well overall. Committers please join the planning meetings.
    • Some QGates are still open, please check.
    • Review together the release preparation

Community Office Hour 2024-07-26

Mathias Brunkow Moser
Eclipse Tractus-X Project Lead

Office Hour meeting minutes

Infrastructure

  • @SebastianBezold -> Wednesday (31.07.2024) the Catena-NG will be deleted! No more access to the consortia environment will be allowed!
    • Friendly reminder from @matbmoser: copy the configuration from the consortia environment argo, so you dont loose it, for the association env;)
  • @hzierer -> Most of E2E Tests are already passed! Great job everyone!
  • @matbmoser -> Don't forget to document the Quality Gate tickets!
  • System team is leaving in wednesday! The participants that will not act as committers please or remove yourself from the list, or contact a project lead. Thank you for you wonderful hard work!

Security team

FOSS

Open planning / community

  • Quality Gates and E2E phase is finishing today (26.07.2024). Make sure to keep your QG tickets updated and
  • @agg3fe -> The TRG checklist is outdated

Community Office Hour 2024-07-05

Consortia Security Team Member

Office Hour meeting minutes

Infrastructure

  • Info from Test / Infrastructure Management CX Association by Harald:
    • SAP DIM follow up meeting with on 8.7.2024 together with Christian Lahmer (SAP) and Evelyn Gurschler and DoubleSlash Net-Business GmbH
    • Work-in-progress with SDE team and importing of test cases
    • Access is currently limited –> would be great to make it accessible and available within Tractus-X
  • Tomasz - Presented about how do you need to publish your API using .tractusx metafile and publish via GitHub pages - API Hub.

Security team

  • Info from security team by Rohan:
    • Reminder about replacement of GitGuardian with TruffleHog, see according pull request to update TX release guideline: #950
    • Reminder about updates to Trivy workflow , see according pull request to update TX release guideline: #949
    • Reminder about about absence of security team members from August 2024
    • Security tools walkthrough in the Committers Meeting of July 5, 2024 (about 20 minutes) - Rohan will announce the walkthrough next week on the TX mailing list while sending out a reminder for the meeting

FOSS

Open planning / community

  • Info by community manager Stephan about the Tractus-X/Catena-X working model and the refinement phase for the 24.12 release
  • Registration is open for the Third Eclipse Tractus-X Community Days on December 05 and 06, 2024, ARENA2036 in Stuttgart!

Security Office Hour 2024-07-04

Consortia Security Team Member

Security Office Hour meeting minutes

Announcements

  • Gitguardian tool for secret scanning will be replaced by TruffleHog. This will be used in parallel with Github's native secret scanning tool.
  • Trivy workflow has been updated to address the failure of workflows
  • Announcement of Security handover during the committer round

Community Office Hour 2024-06-28

Tractus-X Project Lead

Office Hour meeting minutes

Infrastructure

  • Info from Test / Infrastructure Management CX Association by Harald:
    • status of product onboarding and deployment progression to new environment
    • clarifying dependencies, resolving blockers is ongoing
    • handover of test cases to new CX Association Xray
    • Invitation to E2E Test Management Daily beginning Monday (July 1, 2024): frequency determined determined to half an hour every 2nd day
  • Status about current works on API publishing by Tomasz currently in progress: a separate repository to store API docs and publish via GitHub pages - API Hub - was created. He will present the topic a bit more hands on in one of the upcoming office hours

Security team

  • Info from security team by Rohan:
    • Replacement of GitGuardian with TruffleHog, see according pull request to update TX release guideline: #950
    • Updates to Trivy workflow , see according pull request to update TX release guideline: #949
    • Security tools walkthrough in the Committers Meeting of July 5, 2024 (about 20 minutes) - Rohan will announce the walkthrough next week on the TX mailing list while sending out a reminder for the meeting

FOSS

  • Committer Election for Lucas concluded successfully, congratulations and welcome!
  • Don't forget to update the legal docs!! Close the tickets in your repositories if its done: eclipse-tractusx/sig-infra#477

Open planning / community

Discussions

  • Evelyn suggested a consistent storing for environment specific deployment configuration (helm values files) in TX repositories:
    • IF products teams store deployment configuration in TX, it should be stored in a separate directory at root level (/environments) and the notice file should explain it is need for the end-to-end testing of TX releases
    • no deployment configuration other than the one used for the official E2E Testing of TX releases should be kept in TX
    • suggestion is not intended to promote the storing of this configuration in TX but if you do it, do it as proper as possible
    • a benefit from (properly) storing the configuration in TX is the versioning with the TX GitHub releases, allowing to easily trace back the exact configuration used for testing
    • other options for handling environment specific deployment configuration outside of TX were discussed as well as the option of multiple sources for Argo CD was mentioned by Carsten
  • Stephan was wondering about how to handle outdated information on the TX Product Page:
    • product teams should check if the information on the page is still up to date, Stephan will write send a reminder on the TX mailing list
    • Arno mentioned that he would update the products which are still outdated in a couple of weeks, thanks for volunteering!

Community Office Hour 2024-06-21

Mathias Brunkow Moser
Eclipse Tractus-X Project Lead

Office Hour meeting minutes

Infrastructure

Security team

FOSS

Open planning / community

  • Every office hour there will be a slot to talk about the current process of the working model of Tractus-X/Catena-X. With the updates from the community.

Discussions

  • Mermaid version in current docussaurus for the tractus-x webpage do not support specific type block-beta and xychart-beta.
    • Stephan Bauer will test to upgrade the version of docussaurus in the Catena-X e.V. Repository.

Security Office Hour 2024-06-20

Consortia Security Team Member

Security Office Hour meeting minutes

Announcements

  • Reminder about former GitHub Organisation Catenax-ng
  • Reminder to remove any test credentials/sensitive that are present in Catenax-ng
  • Reminder to look for the results of the security scans after migration to Eclipse Tractus-x

Community Office Hour 2024-05-03

Sebastian Bezold
Consortia System Team Member

Office Hour meeting minutes

System team

  • Support needed for overarching CHANGELOG creation for release 24.05. If interested, please get in contact with Stephan Bauer

Security team

  • n/a

FOSS

Open planning / community

  • We are looking for committers to help with the Release QG Check Review for the upcoming release. Please reach out to Roland and Siegfried if you are interested.
  • Check out the meeting invitations for open meetings regarding planning for release 24.12

Discussions

  • Are there defined deadlines for release 24.08 -> No one in the meeting did know of one yet
  • Interoperability and Thread Modelling checks in 24.05?
    • You can approach the Security Team via issue on sig-security
    • Checks, that have been documented in a Consorita Confluence instance, could still take place, but a transparent format should be considered. Some Teams already documented on GitHub.

Community Office Hour 2024-04-26

Fabian Grün
Consortia System Team Member

Office Hour meeting minutes

System team

  • We moved from the former Miro board to the new Board within our Eclipse Tractus-X GitHub organization projects and if you would like to give Feedback feel free to state it in the draft issue
  • Now you can state everytime your topic for the next office hour as a draft issue for each open meeting like the "Office Hour" as described in the info section of the board

Security team

  • Rohan will resume work on Monday, 13-May Alternate contact: Lokesh Gujre , Tim Herres
  • Bug bounty program is still in the works, but we are making progress on it see issue

FOSS

  • Committer Election for Arno Weiß open for voting
  • Please check out the statements to the "Use of AI" in one of our Eclipse Office Hour sessions
  • OCX Conference - Call for speakers is open! Submit your talk here
  • Friendly reminder to the Eclipse Office hours about the process and shared information see here
  • Friendly reminder to check our product notice sections in your documentation and update it if necessary a little example was found within the KIT documentation see here

Open planning / community

  • We are looking for committers to help with the Release QG Check Review for the upcoming release. Please reach out to Roland and Siegfried if you are interested.

Discussions

  • n/a