google / google/go-tpm-tools

Document Third-Party Security Audit Findings by NCC Group as Github issue

Open
#623 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
C
Stars
309
Forks
118
Avg merge
1d 16h
Merged PRs (30d)
33

Description

#### Proposal
Similar to how the Kubernetes project tracks third-party security audit findings (e.g., [Kubernetes 1.24 Third-Party Security Audit Findings](https://github.com/kubernetes/kubernetes/issues/118980)), this issue proposes creating an umbrella issue to track findings from the NCC Group audit and related discussions.

#### Context
- NCC Group conducted a third-party security assessment of Google Confidential Space.
- The public report is available here: https://www.nccgroup.com/research-blog/public-report-google-confidential-space-security-assessment/

#### Rationale
- Publicly documenting and tracking audit findings promotes transparency
- If the audit identified actionable items relevant to Confidential Space users, workloads, or supporting tools (such as those in this repository), tracking them here would be valuable.

Contributor guide

Open the contributing guide

Research direction

Start by reading the NCC Group public report and the linked Kubernetes audit-findings issue to understand the intended tracking format. Done means creating an umbrella issue that records relevant findings and links related discussions, but this issue does not identify specific findings or repository files.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
32/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.