kubernetes / kubernetes/sig-security

TODO: create dedicated google group for CVE feed maintainers

Open
#149 8 comments 0 reactions 1 assignee Claimed by @mtardy View on GitHub
triage/accepted
Dominant language
Go
Stars
249
Forks
82
Avg merge
7d 12h
Merged PRs (30d)
2

Description

While working on the migration of CVE feed generation to Cloud Build, we discovered that the CVE feed prow job [reports its errors ](https://github.com/kubernetes/k8s-test-infra/blob/master/config/jobs/kubernetes/sig-k8s-infra/trusted/sig-security-trusted.yaml#L117)to security-tooling-private@kubernetes.io

Let's break this apart for separation of duties:
* [create a new list](https://github.com/kubernetes/k8s.io/blob/main/groups/sig-security/groups.yaml)
* maybe call it cve-feed-maintainers@kubernetes.io ?
* Populate it with the SIG leads and the CVE feed maintainers
* Update the prow job config to email errors to the new list
* create another new list k8s-infra-staging-sig-security@kubernetes.io (this is the hardcoded required name by [the IAC script](https://github.com/kubernetes/k8s.io/blob/main/infra/gcp/bash/ensure-staging-storage.sh)
* Populate it with cve-feed-maintainers@kubernetes.io so that it will not require future maintenance

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.