Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Categories

Capabilities / Features

Documentation/JIRA

Bahmni Lite v 1.0 Release

1

Trivy Secret & Vulnerability Scanning

Analyze false positives or perform quick fixes on Critical vulnerabilities (First Pass)

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-2416

Status
colourGreen
titleDONE

2

Perform Vulnerability check in CI (build) using Trivy and fail for Critical issues. Add secret scanning using Trivy in all Bahmni repositories

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-2193

Status
colourGreen
titleDONE

3

Machine / Node hardening

OpenSCAP for nodes / machine monitoring

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-2142

Status
colourGreen
titleDONE

4

Apply daily critical security updates automatically (e.g EC2)

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-2412

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-2382

Status
colourYellow
titlenot requiredDEFERRED

5

Firewall

OpenSource / Free option for Bot Management and Traffic Control for Bahmni running on Docker / K8s

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-2413

colour
Status
Yellowtitlenot requiredDEFERRED

6

Document AWS WAF and Bot Management recommendation for Bahmni Lite

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-2414

Yellow
Status
colour
titlenot requiredDEFERRED

7

Security Quality Gates

Explore OWASP Zap for Bahmni Security Testing

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-1961

Status
colourYellow
titlenot requiredDEFERRED

8

Automate Static Code Analysis using DeepSource / SonarQube → Documentation

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-1958

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-1959

Yellow
Status
colour
titlenot requiredDEFERRED

9

Data Protection

Protect patient documents behind Login (only for older RPM based installation since docker and k8s no longer have this issue)

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-2417

Status
colourYellow
titlenot requiredDEFERRED

10

Encrypt documents at rest (S3/FileSystem/Connected Storage/etc) e.g. Patient Documents

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-2418

Status
colourYellow
titlenot requiredDEFERRED

11

Identity Management

Mitigate default credentials risk

  • Ensure Change password on first login e.g. superman

  • Remove default creds from code e.g. .env, values.yaml etc

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-1960

Yellow
Status
colour
titlenot requiredDEFERRED

12

Cloud/Infra

Document recommendations on General Cloud hygiene

Status
colourYellow
titlenot requiredDEFERRED

13

Document Approach on Reporting security incident (Slack, DL etc)

Status
colourYellowGreen
titlenot requiredDONE

14

Source Code Fixes

Fix hip service critical vulnerabilities

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-2550

Status
colourRed
titleABDM
Status
colourRed
titlerequired

15

Fix hiu backend critical vulnerabilities

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-2551

Status
colourRed
titleABDM
Status
colourRed
titlerequired

16

Fix hiu-ui critical vulnerabilities

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-2552

Status
colourRed
titleABDM
Status
colourRed
titlerequired

17

Fix critical vulnerabilities in ABHA verification repo.

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-2553

Status
colourRed
titleABDM
Status
colourRed
titlerequired

18

Fix critical vulnerabilities in Hiu-db code

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-2554

Status
colourRed
titleABDM
Status
colourRed
titlerequired

19

Fix Critical Vulnerabilities in Appointments, Bahmni-lab, Bahmni-web, implementer-interface and patient-Documents images/jars

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-2557

Status
colourRed
titlerequired

20

Fix Critical Vulnerabilities in the crater-atomfeed repo

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-2786

Status
colourRed
titlerequired

...