-
Notifications
You must be signed in to change notification settings - Fork 703
[Initiative]: Update Project Security Guidelines #2186
Copy link
Copy link
Open
Labels
kind/initiativeAn initiative or an item related to imitative processesAn initiative or an item related to imitative processesneeds-triageIndicates an issue or PR that has not been triaged yet (has a 'triage/foo' label applied)Indicates an issue or PR that has not been triaged yet (has a 'triage/foo' label applied)tag/security-and-complianceTAG Security and ComplianceTAG Security and Compliance
Metadata
Metadata
Assignees
Labels
kind/initiativeAn initiative or an item related to imitative processesAn initiative or an item related to imitative processesneeds-triageIndicates an issue or PR that has not been triaged yet (has a 'triage/foo' label applied)Indicates an issue or PR that has not been triaged yet (has a 'triage/foo' label applied)tag/security-and-complianceTAG Security and ComplianceTAG Security and Compliance
Type
Fields
Give feedbackNo fields configured for issues without a type.
Projects
StatusShow more project fields
New
StatusShow more project fields
status/new
StatusShow more project fields
No status
StatusShow more project fields
No status
StatusShow more project fields
No status
Name
Update Project Security Guidelines and Templates
Short description
Update the security guidelines and templates on contribute.cncf.io
Responsible group
TAG Security and Compliance
Does the initiative belong to a subproject?
No
Subproject name
No response
Primary contact
@jkjell
Additional contacts
No response
Initiative description
A continuation of cncf/tag-security#1260 to update the guidance found on the CNCF's contribute.cncf.io for best practices around project's Security Hygiene. Additionally, there are templates for some security sections that may also need to be updated.
While all areas of the current guidance should be updated for relevancy and accuracy, some potential new areas. TAG Security and Compliance often receives questions around and can offer authoritative guidance on:
Additional topics and areas may considered upon TAG S&C leadership agreement and community interest.
Deliverable(s) or exit criteria
Tracking document for meeting and progress
https://notes.cncf.io/3KfWEuEjRdOZ7E-g1VMirQ