-
Epic
-
Resolution: Unresolved
-
Undefined
-
None
-
None
-
None
-
Source Verification Policies: Git
-
False
-
-
False
-
In Progress
-
SECFLOWOTL-229 - Source Verification Policies
-
17% To Do, 50% In Progress, 33% Done
-
-
Epic Goal
- Refactor the GPG verification feature into more generic source verification policies permitting configurable verification of git repositories
Why is this important?
- It permits verifying the history, not just the tip of the targetRevision - more secure
- It eventually permits other kinds of verification than GPG
Definition of Ready
- The epic has been broken down into stories. Stories have been scoped.
- The epic has been stack ranked.
Definition of Done
- Code Complete:
- All code has been written, reviewed, and approved.
- Tested:
- Unit tests have been written and passed.
- Integration tests have been completed.
- System tests have been conducted, and all critical bugs have been fixed.
- Tested on OpenShift either upstream or downstream on a local build
- Documentation:
- User documentation or release notes have been written.
- Build:
- Code has been successfully built and integrated into the main repository / project
- Review:
- Code has been peer-reviewed and meets coding standards.
- All acceptance criteria defined in the user story have been met.
- Tested by reviewer on OpenShift
- Deployment:
- The feature has been deployed on OpenShift cluster for testing
- Acceptance:
- Product Manager or stakeholder has reviewed and accepted the work.
- blocks
-
GITOPS-8245 GPG validation for multi-source apps
-
- New
-