Document Third-Party Security Audit Findings by NCC Group as Github issue
- Dominant language
- C
- Stars
- 309
- Forks
- 118
- Avg merge
- 1d 16h
- Merged PRs (30d)
- 33
Description
#### Proposal
Similar to how the Kubernetes project tracks third-party security audit findings (e.g., [Kubernetes 1.24 Third-Party Security Audit Findings](https://github.com/kubernetes/kubernetes/issues/118980)), this issue proposes creating an umbrella issue to track findings from the NCC Group audit and related discussions.
#### Context
- NCC Group conducted a third-party security assessment of Google Confidential Space.
- The public report is available here: https://www.nccgroup.com/research-blog/public-report-google-confidential-space-security-assessment/
#### Rationale
- Publicly documenting and tracking audit findings promotes transparency
- If the audit identified actionable items relevant to Confidential Space users, workloads, or supporting tools (such as those in this repository), tracking them here would be valuable.
Contributor guide
Research direction
Start by reading the NCC Group public report and the linked Kubernetes audit-findings issue to understand the intended tracking format. Done means creating an umbrella issue that records relevant findings and links related discussions, but this issue does not identify specific findings or repository files.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 32/100