Add survey data for "Showcasing Frictionless Secure Coding Success Stories and Pain Points in CNCF Projects"#2185
Conversation
Signed-off-by: Julien Semaan <jul.semaan@gmail.com>
Signed-off-by: Julien Semaan <jul.semaan@gmail.com>
276d2e7 to
6d2c16f
Compare
|
|
||
| * Secure DevEx Pain Point & Usability Report: Findings from maintainers and contributors, with actionable recommendations. | ||
| * Maturity Case Studies: Extracted lessons from established CNCF projects to illustrate effective approaches others can adopt. | ||
| * ~~Maturity Case Studies: Extracted lessons from established CNCF projects to illustrate effective approaches others can adopt.~~ |
There was a problem hiding this comment.
Just curiosity. What is "~~" for?
There was a problem hiding this comment.
I believe it is the GitHub Markdown syntax for strikethrough text. Maybe the next bullet should just be a non-formatted append to this bullet to make it a little more clear? Or something like "Abandoned - Maturity Case Studies"?
There was a problem hiding this comment.
If this bullet is supposed to be removed, feel free to update the PR.
|
|
||
| The data suggests five headline findings: | ||
|
|
||
| 1. **Awareness of TAG S&C guidance is low.** Most respondents rated their familiarity at the low end of the scale. |
There was a problem hiding this comment.
TAG S&C should be the full name - "TAG Security and Compliance"
danieloh30
left a comment
There was a problem hiding this comment.
I added a few minor comments though, the others look good to me. Well done @julsemaan
Signed-off-by: Julien Semaan <jul.semaan@gmail.com>
|
@danieloh30, please take another look. Thanks! |
danieloh30
left a comment
There was a problem hiding this comment.
Cool! Looks great to me. Thanks for the updates!
|
lgtm. Too bad we haven't been able to get more results. Based on this report it's clear that DevEx is an important factor in adopting (or the lack of) security so there are definitely opportunities for follow up initiatives in this area |
Closes #1943