cncf / cncf/toc

[Initiative]: Update Project Security Guidelines

Open
#2,186 4 comments 2 reactions 2 assignees Claimed by @Satarupa22-SD View on GitHub
init/in-progress kind/initiative tag/security-and-compliance
Dominant language
HTML
Stars
1.9k
Forks
724
Avg merge
6d 12h
Merged PRs (30d)
4

Description

### Name

Update Project Security Guidelines and Templates

### Short description

Update the security guidelines and templates on contribute.cncf.io

### Responsible group

TAG Security and Compliance

### Does the initiative belong to a subproject?

No

### Subproject name

_No response_

### Primary contact

@jkjell

### Additional contacts

_No response_

### Initiative description

A continuation of https://github.com/cncf/tag-security/issues/1260 to update the guidance found on the CNCF's contribute.cncf.io for best practices around project's [Security Hygiene](https://contribute.cncf.io/projects/best-practices/security/security-hygiene). Additionally, there are [templates](https://contribute.cncf.io/projects/best-practices/templates/#available-templates) for some security sections that may also need to be updated.

While all areas of the current guidance should be updated for relevancy and accuracy, some potential new areas. TAG Security and Compliance often receives questions around and can offer authoritative guidance on:

- [Security Baseline](https://baseline.openssf.org/)
- SBOM and SLSA Build Provenance generation
- Dependency review and selection
- GitHub Actions Workflows security

Additional topics and areas may considered upon TAG S&C leadership agreement and community interest.

### Deliverable(s) or exit criteria

- [ ] Review of current guidance for relevancy and accuracy
- [ ] Creation of well defined tasks to update specific existing sections
- [ ] Creation of well defined tasks to add new relevant sections
- [ ] New sections added for:
- [ ] [Security Baseline](https://baseline.openssf.org/)
- [ ] SBOM and SLSA Build Provenance generation
- [ ] Dependency review and selection
- [ ] GitHub Actions Workflows security

### Tracking document for meeting and progress

https://notes.cncf.io/3KfWEuEjRdOZ7E-g1VMirQ

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.