Document OJSI-196 vulnerability
[ccsdk/distribution.git] / docs / release-notes.rst
1 .. This work is licensed under a Creative Commons Attribution 4.0 International License.
2
3 Release Notes
4 #############
5
6 Version 0.4.3
7 *************
8 :Release Date: 2019-06-13
9
10 **New Features**
11
12 The full list of Dublin epics and user stories for CCSDK maybe be found at <https://jira.onap.org/issues/?filter=11802>.
13
14 The following list summarizes some of the most significant epics:
15
16 +-------------+------------------------------------------------+
17 | Jira #      | Abstract                                       |
18 +=============+================================================+
19 | [CCSDK-575] | Improve E2E Process Automation                 |
20 +-------------+------------------------------------------------+
21 | [CCSDK-840] | S3P - Footprint Optimization                   |
22 +-------------+------------------------------------------------+
23 | [CCSDK-859] | Update to OpenDaylight Fluorine                |
24 +-------------+------------------------------------------------+
25 | [CCSDK-929] | 5G Use Case                                    |
26 +-------------+------------------------------------------------+
27 | [CCSDK-930] | CCVPN Use Case Extension                       |
28 +-------------+------------------------------------------------+
29
30
31 **Bug Fixes**
32 The full list of bug fixes in the CCSDK Dublin release may be found at <https://jira.onap.org/issues/?filter=11804>
33
34 **Known Issues**
35 The full list of known issues in CCSDK may be found in the ONAP Jira at <https://jira.onap.org/issues/?filter=11341>
36
37 **Security Notes**
38
39 *Fixed Security Issues*
40
41 *Known Security Issues*
42
43         * In default deployment CCSDK (netbox-nginx) exposes HTTP port 30420 outside of cluster. [`OJSI-160 <https://jira.onap.org/browse/OJSI-160>`_]
44         * In default deployment CCSDK (cds-ui) exposes HTTP port 30497 outside of cluster. [`OJSI-196 <https://jira.onap.org/browse/OJSI-196>`_]
45
46 *Known Vulnerabilities in Used Modules*
47
48 Quick Links:
49         - `CCSDK project page <https://wiki.onap.org/display/DW/Common+Controller+SDK+Project>`_
50
51         - `Passing Badge information for CCSDK <https://bestpractices.coreinfrastructure.org/en/projects/1630>`_
52
53         - `Project Vulnerability Review Table for CCSDK <https://wiki.onap.org/pages/viewpage.action?pageId=51282469>`_
54
55 Version: 0.3.3
56 **************
57
58 :Release Date: 2019-01-30
59
60 ** Bug Fixes **
61 The following bugs are fixed in the CCSDK Casablanca January 2019 maintenance release:
62
63 +-------------+-------------------------------------------------------------------------------+
64 | Jira #      | Abstract                                                                      |
65 +=============+===============================================================================+
66 | [CCSDK-727] | Do not prepend "sub" for subnet net id                                        |
67 +-------------+-------------------------------------------------------------------------------+
68 | [CCSDK-728] | Self serve DG adjustement for unassign                                        |
69 +-------------+-------------------------------------------------------------------------------+
70 | [CCSDK-740] | Restore inventory-response-item definition to the original version            |
71 +-------------+-------------------------------------------------------------------------------+
72 | [CCSDK-765] | Upgrade jackson version to 2.8.9                                              |
73 +-------------+-------------------------------------------------------------------------------+
74 | [CCSDK-777] | Release version contains some snapshots                                       |
75 +-------------+-------------------------------------------------------------------------------+
76 | [CCSDK-843] | Compile error due to old snapshot dependency                                  |
77 +-------------+-------------------------------------------------------------------------------+
78 | [CCSDK-935] | restapicall JsonParser failed if response contains : as part of response body |
79 +-------------+-------------------------------------------------------------------------------+
80
81 **Known Issues**
82 The full list of known issues in CCSDK may be found in the ONAP Jira at <https://jira.onap.org/issues/?filter=11341>
83
84 Quick Links:
85    - `CCSDK project page <https://wiki.onap.org/display/DW/Common+Controller+SDK+Project>`_
86
87    - `Passing Badge information for CCSDK <https://bestpractices.coreinfrastructure.org/en/projects/1630>`_
88
89    - `Project Vulnerability Review Table for CCSDK <https://wiki.onap.org/pages/viewpage.action?pageId=45300857>`_
90
91 Version: 0.3.2
92 **************
93
94 :Release Date: 2018-11-30
95
96 **New Features**
97
98 The full list of Casablanca epics and user stories for CCSDK maybe be found at <https://jira.onap.org/issues/?filter=11516>.
99
100 The following list summarizes some of the most significant epics:
101
102 +-------------+------------------------------------------------+
103 | Jira #      | Abstract                                       |
104 +=============+================================================+
105 | [CCSDK-279] | Update to OpenDaylight Oxygen release          |
106 +-------------+------------------------------------------------+
107 | [CCSDK-357] | Develop Controller Design Studio in Casablanca |
108 +-------------+------------------------------------------------+
109 | [CCSDK-324] | Enhancements to support CCVPN use case         |
110 +-------------+------------------------------------------------+
111 | [CCSDK-288] | Usability Enhancements                         |
112 +-------------+------------------------------------------------+
113
114 **Bug Fixes**
115 The full list of bug fixes in the CCSDK Casablanca release may be found at <https://jira.onap.org/issues/?filter=11544>
116
117 **Known Issues**
118 The full list of known issues in CCSDK may be found in the ONAP Jira at <https://jira.onap.org/issues/?filter=11341>
119
120 Quick Links:
121         - `CCSDK project page <https://wiki.onap.org/display/DW/Common+Controller+SDK+Project>`_
122
123         - `Passing Badge information for CCSDK <https://bestpractices.coreinfrastructure.org/en/projects/1630>`_
124
125         - `Project Vulnerability Review Table for CCSDK <https://wiki.onap.org/pages/viewpage.action?pageId=45300857>`_
126
127 Version: 0.2.4
128 **************
129
130
131 :Release Date: 2018-06-07
132
133
134
135 **New Features**
136
137 The full list of Beijing Epics and user stories for CCSDK may be found at <https://jira.onap.org/issues/?filter=10792>.  The following
138 list summarizes some of the more critical features:
139
140 +--------------+-----------------------------------------------------------------------------------------------+
141 | Jira #       | Abstract                                                                                      |
142 +==============+===============================================================================================+
143 | [CCSDK-222]  | Ansible server support <https://jira.onap.org/browse/CCSDK-222>                               |
144 +--------------+-----------------------------------------------------------------------------------------------+
145 | [CCSDK-191]  | enable fast loading of graphs <https://jira.onap.org/browse/CCSDK-191>                        |
146 +--------------+-----------------------------------------------------------------------------------------------+
147 | [CCSDK-179]  | Upgrade CCSDK ODL containers to Nitrogen <https://jira.onap.org/browse/CCSDK-179>             |
148 +--------------+-----------------------------------------------------------------------------------------------+
149 | [CCSDK-177]  | Upgrade sli/northbound to Nitrogen <https://jira.onap.org/browse/CCSDK-177>                   |
150 +--------------+-----------------------------------------------------------------------------------------------+
151 | [CCSDK-176]  | Upgrade sli/adaptors to Nitrogen <https://jira.onap.org/browse/CCSDK-176>                     |
152 +--------------+-----------------------------------------------------------------------------------------------+
153 | [CCSDK-175]  | Upgrade sli/core to Nitrogen <https://jira.onap.org/browse/CCSDK-175>                         |
154 +--------------+-----------------------------------------------------------------------------------------------+
155 | [CCSDK-174]  | Update ccsdk parent to support Nitrogen parent poms <https://jira.onap.org/browse/CCSDK-174>  |
156 +--------------+-----------------------------------------------------------------------------------------------+
157 | [CCSDK-172]  | Ability to call Ansible playbook from directed graph <https://jira.onap.org/browse/CCSDK-172> |
158 +--------------+-----------------------------------------------------------------------------------------------+
159
160 **Bug Fixes**
161
162 The full list of bug fixes in the CCSDK Beijing release may be found at <https://jira.onap.org/issues/?filter=11117>
163
164 **Known Issues**
165
166 +--------------+-----------------------------------------------------------------------------------------------------+
167 | Jira #       | Abstract                                                                                            |
168 +==============+=====================================================================================================+
169 | [CCSDK-136]  | pgaas is dependent on location\_prefix being all lowercase <https://jira.onap.org/browse/CCSDK-136> |
170 +--------------+-----------------------------------------------------------------------------------------------------+
171
172 **Security Notes**
173
174 CCSDK code has been formally scanned during build time using NexusIQ and all Critical vulnerabilities have been addressed, items that remain open have been assessed for risk and determined to be false positive. The CCSDK open Critical security vulnerabilities and their risk assessment have been documented as part of the `project <https://wiki.onap.org/pages/viewpage.action?pageId=28379011>`_.
175
176 Quick Links:
177         - `CCSDK project page <https://wiki.onap.org/display/DW/Common+Controller+SDK+Project>`_
178
179         - `Passing Badge information for CCSDK <https://bestpractices.coreinfrastructure.org/en/projects/1630>`_
180
181         - `Project Vulnerability Review Table for CCSDK <https://wiki.onap.org/pages/viewpage.action?pageId=28379011>`_
182
183 **Upgrade Notes**
184
185 N/A
186
187 **Deprecation Notes**
188
189 N/A
190
191 **Other**
192
193 N/A
194
195
196 Version: 0.1.0
197 **************
198
199
200 :Release Date: 2017-11-16
201
202
203
204 **New Features**
205
206 The Common Controller SDK provides the following functionality :
207    - Service Logic Interpreter
208    - Database access library (dblib)
209    - Service Logic test api (sliapi)
210    - MD-SAL data query adaptor
211    - SQL query adaptor
212    - Resource allocator
213    - SDC interface
214    - DMAAP interface
215    - REST API adaptor
216
217
218 **Bug Fixes**
219
220 **Known Issues**
221    - `CCSDK-110 <https://jira.onap.org/browse/CCSDK-110>`_ Resolve license issues in dashboard project
222    - `CCSDK-136 <https://jira.onap.org/browse/CCSDK-136>`_ pgaas is dependent on location_prefix being all lowercase
223    - `CCSDK-137 <https://jira.onap.org/browse/CCSDK-137>`_ isolate deprecated methods
224
225 **Security Issues**
226    You may want to include a reference to CVE (Common Vulnerabilities and Exposures) `CVE <https://cve.mitre.org>`_
227
228
229 **Upgrade Notes**
230
231 **Deprecation Notes**
232
233 **Other**