Skip to content

[Security Review] kcp #1815

Description

@embik

Project Name: kcp

Github URL: https://github.com/kcp-dev/kcp

CNCF project stage and issue (NA if not applicable): sandbox (cncf/sandbox#47) (we are looking for this joint security review to apply for incubation)

Security Provider: no

  • Identify team
    • Project security lead
    • Lead security reviewer
    • 1 or more additional reviewer(s)
    • Every reviewer has read security reviewer guidelines and stated declaration of conflict
    • Sign off by facilitator on reviewer conflicts
  • Create slack channel (e.g. #sec-assess-projectname)
  • Project lead provides draft document - see outline
  • "Naive question phase" Lead Security Reviewer asks clarifying questions
  • Assign issue to security reviewers
  • Initial review
  • Presentation & discussion
  • Share draft findings with project
  • Assessment summary and doc checked into /assessments/projects/project-name (require at least 1 co-chair approval)
  • CNCF TOC presentation (if requested by TOC)

Metadata

Metadata

Assignees

No one assigned

    Labels

    needs-kindIndicates an issue or PR that is missing an issue type or kind (a kind/foo label)needs-triageIndicates an issue or PR that has not been triaged yet (has a 'triage/foo' label applied)review/securityProject Security Reviewtag/security-and-complianceTAG Security and Compliance

    Type

    No type
    No fields configured for issues without a type.

    Projects

    Status
    New
    Status
    No status
    Status
    No status
    Status
    No status
    Status
    In Progress

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions