kubernetes / kubernetes/sig-security

Kubernetes Third-Party Security Audit for 2025 (tracking issue)

Open
#104 28 comments 0 reactions 0 assignees View on GitHub
sig/security
Dominant language
Go
Stars
249
Forks
82
Avg merge
7d 12h
Merged PRs (30d)
2

Description

Tracking issue for the Kubernetes third-party security audit for 2025:
- [x] Define audit scope and provide to the Open Source Technology Improvement Fund (OSTIF)
- [x] OSTIF Creates RFP
- [x] SIG Security Third-Party Audit subproject reviews RFP
- [x] Vendor assessment
- [x] Release vendor selection
- [x] Create private Slack channel for vendor and subproject
- [x] Vendor conducts audit
- [x] Coordinate SME as contacts for vendor
- [x] Send findings to SRC
- [ ] Findings review with SIG Security
- [ ] Publish findings

/sig security

Contributor guide

Open the contributing guide

Research direction

Review issue #104 and its checklist, starting with the remaining SIG Security findings review and publication tasks. Coordinate with SIG Security to determine the approved audit findings and publish them; done means both unchecked checklist items are complete.

Written by the indexing model from the issue text.

Assessment

Tech stack
kubernetes
Domain
documentation, security
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.