-
Notifications
You must be signed in to change notification settings - Fork 665
Update templates to suggest a joint security assessment and governance review #1929
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
4717f40
906418e
b3bb434
a3b3005
eca6acb
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -69,10 +69,14 @@ Completion of this due diligence document, resolution of concerns raised, and pr | |
|
|
||
| ## Governance and Maintainers | ||
|
|
||
| Note: this section may be augmented by the completion of a Governance Review from the Project Reviews subproject. | ||
| Note: this section may be augmented by the completion of a Governance Review from the Project Reviews subproject if completed as a suggested item prior to application. | ||
|
|
||
| ### Suggested | ||
|
|
||
| - [ ] **Complete a Governance Review with the Project Reviews subproject** | ||
|
|
||
| <!-- (Project assertion goes here) --> | ||
|
|
||
| - [ ] **Governance has continuously been iterated upon by the project as a result of their experience applying it, with the governance history demonstrating evolution of maturity alongside the project's maturity evolution.** | ||
|
|
||
| <!-- (Project assertion goes here) --> | ||
|
|
@@ -217,10 +221,14 @@ Note: this section may be augmented by the completion of a Governance Review fro | |
|
|
||
| ## Security | ||
|
|
||
| Note: this section may be augmented by a joint-assessment performed by TAG Security and Compliance. | ||
| Note: this section may be augmented by a joint-assessment performed by TAG Security and Compliance if completed as a suggested item prior to application. | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. "Suggested item within the application prior to submission" |
||
|
|
||
| ### Suggested | ||
|
|
||
| - [ ] **Complete a [joint security assessment](https://tag-security.cncf.io/community/assessments/guide/#joint-assessment) with TAG Security and Compliance** | ||
|
|
||
| <!-- (Project assertion goes here) --> | ||
|
|
||
| - [ ] **Achieving OpenSSF Best Practices silver or gold badge.** | ||
|
|
||
| <!-- (Project assertion goes here) --> | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -69,10 +69,14 @@ Completion of this due diligence document, resolution of concerns raised, and pr | |
|
|
||
| ## Governance and Maintainers | ||
|
|
||
| Note: this section may be augmented by the completion of a Governance Review from the Project Reviews subproject. | ||
| Note: this section may be augmented by the completion of a Governance Review from the Project Reviews subproject if completed as a suggested item prior to application. | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. "Suggested item within the application prior to submission" |
||
|
|
||
| ### Suggested | ||
|
|
||
| - [ ] **Complete a Governance Review with the Project Reviews subproject** | ||
|
|
||
| <!-- (Project assertion goes here) --> | ||
|
|
||
| - [ ] **Governance has continuously been iterated upon by the project as a result of their experience applying it, with the governance history demonstrating evolution of maturity alongside the project's maturity evolution.** | ||
|
|
||
| <!-- (Project assertion goes here) --> | ||
|
|
@@ -209,13 +213,15 @@ Note: this section may be augmented by the completion of a Governance Review fro | |
|
|
||
| ## Security | ||
|
|
||
| Note: this section may be augmented by a joint-assessment performed by TAG Security and Compliance if completed as a suggested item prior to application. | ||
|
|
||
| ### Suggested | ||
|
|
||
| N/A | ||
| - [ ] **Complete a joint security assessment with TAG Security and Compliance** | ||
|
|
||
| ### Required | ||
| <!-- (Project assertion goes here) --> | ||
|
|
||
| Note: this section may be augmented by a joint-assessment performed by TAG Security and Compliance. | ||
| ### Required | ||
|
|
||
| - [ ] **Clearly defined and discoverable process to report security issues.** | ||
|
|
||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -52,10 +52,14 @@ Completion of this due diligence document, resolution of concerns raised, and pr | |
|
|
||
| ## Governance and Maintainers | ||
|
|
||
| Note: this section may be augmented by the completion of a Governance Review from the Project Reviews subproject. | ||
| Note: this section may be augmented by the completion of a Governance Review from the Project Reviews subproject if completed as a suggested item prior to application. | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. "Suggested item within the application prior to submission" |
||
|
|
||
| ### Suggested | ||
|
|
||
| - [ ] **Complete a Governance Review with the Project Reviews subproject** | ||
|
|
||
| <!-- (TOC Evaluation goes here) --> | ||
|
|
||
| - [ ] **Governance has continuously been iterated upon by the project as a result of their experience applying it, with the governance history demonstrating evolution of maturity alongside the project's maturity evolution.** | ||
|
|
||
| <!-- (TOC Evaluation goes here) --> | ||
|
|
@@ -204,14 +208,19 @@ N/A | |
|
|
||
| ## Security | ||
|
|
||
| Note: this section may be augmented by a joint-assessment performed by TAG Security and Compliance. | ||
| Note: this section may be augmented by a joint-assessment performed by TAG Security and Compliance if completed as a suggested item prior to application. | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. "Suggested item within the application prior to submission" |
||
|
|
||
|
|
||
| ### Suggested | ||
|
|
||
| - [ ] **Achieving OpenSSF Best Practices silver or gold badge.** | ||
|
|
||
| <!-- (TOC Evaluation goes here) --> | ||
|
|
||
| - [ ] **Complete a joint security assessment with TAG Security and Compliance** | ||
|
|
||
| <!-- (TOC Evaluation goes here) --> | ||
|
|
||
| ### Required | ||
|
|
||
| - [ ] **Clearly defined and discoverable process to report security issues.** | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -50,10 +50,14 @@ Completion of this due diligence document, resolution of concerns raised, and pr | |
|
|
||
| ## Governance and Maintainers | ||
|
|
||
| Note: this section may be augmented by the completion of a Governance Review from the Project Reviews subproject. | ||
| Note: this section may be augmented by the completion of a Governance Review from the Project Reviews subproject if completed as a suggested item prior to application. | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. "Suggested item within the application prior to submission" |
||
|
|
||
| ### Suggested | ||
|
|
||
| - [ ] **Complete a Governance Review with the Project Reviews subproject** | ||
|
|
||
| <!-- (TOC Evaluation goes here) --> | ||
|
|
||
| - [ ] **Governance has continuously been iterated upon by the project as a result of their experience applying it, with the governance history demonstrating evolution of maturity alongside the project's maturity evolution.** | ||
|
|
||
| <!-- (TOC Evaluation goes here) --> | ||
|
|
@@ -190,13 +194,15 @@ Note: this section may be augmented by the completion of a Governance Review fro | |
|
|
||
| ## Security | ||
|
|
||
| Note: this section may be augmented by a joint-assessment performed by TAG Security and Compliance if completed as a suggested item prior to application. | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. "Suggested item within the application prior to submission" |
||
|
|
||
| ### Suggested | ||
|
|
||
| N/A | ||
| - [ ] **Complete a joint security assessment with TAG Security and Compliance** | ||
|
|
||
| ### Required | ||
| <!-- (TOC Evaluation goes here) --> | ||
|
|
||
| Note: this section may be augmented by a joint-assessment performed by TAG Security and Compliance. | ||
| ### Required | ||
|
|
||
| - [ ] **Clearly defined and discoverable process to report security issues.** | ||
|
|
||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Please be more explicit on who is suggesting the Governance Review
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
"Suggested item within the application prior to submission" -- we may need to review overall language in the application to reduce confusion for multiple geos/cultures