Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Categories

Capabilities / Features

Documentation/JIRA

Bahmni Lite v 1.0 Release

1

Trivy Secret & Vulnerability Scanning

Analyze false positives or perform quick fixes on Critical vulnerabilities (First Pass)

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-2416

Status
colourGreen
titleDONE

2

Perform Vulnerability check in CI (build) using Trivy and fail for Critical issues. Add secret scanning using Trivy in all Bahmni repositories

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-2193

Status
colourGreen
titleDONE

3

Machine / Node hardening

OpenSCAP for nodes / machine monitoring

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-2142

Status
colourGreen
titleDONE

4

Apply daily critical security updates automatically (e.g EC2)

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-2412

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-2382

Status
titleDEFERRED

5

Firewall

OpenSource / Free option for Bot Management and Traffic Control for Bahmni running on Docker / K8s

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-2413

Status
titleDEFERRED

6

Document AWS WAF and Bot Management recommendation for Bahmni Lite

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-2414

Status
titleDEFERRED

7

Security Quality Gates

Explore OWASP Zap for Bahmni Security Testing

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-1961

Status
titleDEFERRED

8

Automate Static Code Analysis using DeepSource / SonarQube → Documentation

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-1958

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-1959

Status
titleDEFERRED

9

Data Protection

Protect patient documents behind Login (only for older RPM based installation since docker and k8s no longer have this issue)

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-2417

Status
titleDEFERREDNot APPLICABLE

10

Encrypt documents at rest (S3/FileSystem/Connected Storage/etc) e.g. Patient Documents

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-2418

Status
titleDEFERRED

11

Identity Management

Mitigate default credentials risk

  • Ensure Change password on first login e.g. superman

  • Remove default creds from code e.g. .env, values.yaml etc

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-1960

Status
titleDEFERRED

12

Cloud/Infra

Document recommendations on General Cloud hygiene

Status
titleDEFERREDPARTIAL DONE

13

Document Approach on Reporting security incident (Slack, DL etc)

Status
colourGreen
titleDONE

14

Source Code Fixes

Fix hip service critical vulnerabilities

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-2550

Status
colourRed
titleABDM
Status
colourRedGreen
titlerequiredDONE

15

Fix hiu backend critical vulnerabilities

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-2551

Status
colourRed
titleABDM
Status
colourRedGreen
titlerequiredDONE

16

Fix hiu-ui critical vulnerabilities

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-2552

Status
colourRed
titleABDM
Status
colourRedGreen
titlerequiredDONE

17

Fix critical vulnerabilities in ABHA verification repo.

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-2553

Status
colourRed
titleABDM
Status
colourRedGreen
titlerequiredDONE

18

Fix critical vulnerabilities in Hiu-db code

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-2554

Status
colourRed
titleABDM
Status
colourRedGreen
titlerequiredDONE

19

Fix Critical Vulnerabilities in Appointments, Bahmni-lab, Bahmni-web, implementer-interface and patient-Documents images/jars

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-2557

Status
colourRed
titlerequired
Status
colourGreen
titleDONE

20

Fix Critical Vulnerabilities in the crater-atomfeed repo

Jira Legacy
serverSystem JIRA
serverId32584f0f-f83d-3b0b-b91f-826465c6b0b8
keyBAH-2786

Status
colourRed
titlerequired
Status
colourGreen
titleDONE