cncf / cncf/toc

[Initiative]: Kyverno Joint Security Assessment

Open
#1,703 35 comments 0 reactions 1 assignee Claimed by @sublimino View on GitHub
kind/initiative review/security tag/security-and-compliance
Dominant language
HTML
Stars
1.9k
Forks
724
Avg merge
6d 12h
Merged PRs (30d)
4

Description

(Note: this was filed with the [initiative template](https://github.com/cncf/toc/blob/main/.github/ISSUE_TEMPLATE/initiative.yml) and updated to the [joint security assessment template](https://github.com/cncf/toc/blob/main/.github/ISSUE_TEMPLATE/joint-security-review.yaml) on 1 Oct by @evankanderson. Some fields will still need to be filled out.)

### Project Name

Kyverno

### GitHub URL

https://github.com/kyverno/kyverno

### Project Security Contacts

@JimBugwadia , @realshuting

## Getting Started

### Self Assessment Link

https://github.com/cncf/toc/tree/main/projects/kyverno/security-assessment/self-assessment.md

### CNCF Project Stage

Incubation

### Security Provider

Yes

### Security Review Checklist

- [x] Identify team
- [x] Project's assessment lead @realshuting / @JimBugwadia
- [x] Lead security reviewer @sublimino
- [x] 1 or more additional reviewer(s) @JustinCappos @sunstonesecure-robert @eddie-knight Observers: @jackap @trumant @camilaavilarinho @tturquette
- [x] Every reviewer has read [security reviewer guidelines](https://tag-security.cncf.io/community/assessments/guide/security-reviewer/) and stated declaration of conflict
- [x] Sign off by facilitator on reviewer conflicts
- [x] Create slack channel (e.g. #sec-assess-projectname)
- [x] "Naive question phase" Lead Security Reviewer asks clarifying questions
- [ ] Assign issue to security reviewers
- [ ] Initial review
- [ ] Presentation & discussion
- [ ] Share draft findings with project
- [ ] Assessment summary and doc checked into `/projects/project-name/assessments/` (require at least 1 co-chair approval)
- [ ] CNCF TOC presentation (if requested by TOC)

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.