|
Re: FYI: New Training Course on Diversity in Open Source
Thanks, this is a discussion point for the TOC but I think the reality will be a roll out in 2021 at some level.
Also thank you Arun for pushing me to get this done in time for kubecon :)
Please
Thanks, this is a discussion point for the TOC but I think the reality will be a roll out in 2021 at some level.
Also thank you Arun for pushing me to get this done in time for kubecon :)
Please
|
By
Chris Aniszczyk
·
#5524
·
|
|
Re: FYI: New Training Course on Diversity in Open Source
Should we make it mandatory (which I think is a good idea), it would be useful to cross reference kubernetes who took the same approach for all leaders (I did the course as part of product security).
Should we make it mandatory (which I think is a good idea), it would be useful to cross reference kubernetes who took the same approach for all leaders (I did the course as part of product security).
|
By
Luke A Hinds <lhinds@...>
·
#5523
·
|
|
Re: FYI: New Training Course on Diversity in Open Source
Chris,
I just completed the course and it's extremely valuable. As already mentioned and noted for next TOC agenda, this should be a must for all leadership positions in CNCF.
It took me > 1 hour to
Chris,
I just completed the course and it's extremely valuable. As already mentioned and noted for next TOC agenda, this should be a must for all leadership positions in CNCF.
It took me > 1 hour to
|
By
Arun Gupta
·
#5522
·
|
|
Re: [cncf-sig-security] [cncf-toc] Vulnerability scanning for CNCF projects
Same! We would love a presentation! Shubhra please add itself to the agenda for an upcoming meeting in December.
The Security SIG group meets every Wednesday at 10:00am PT (USA Pacific)
Meeting
Same! We would love a presentation! Shubhra please add itself to the agenda for an upcoming meeting in December.
The Security SIG group meets every Wednesday at 10:00am PT (USA Pacific)
Meeting
|
By
Emily Fox
·
#5521
·
|
|
Re: Vulnerability scanning for CNCF projects
Add me as well.
I am one of the maintainers on bandit (python ast based security linter) which hits around 25k downloads a day, so I have a fair amount of experience in what works / does not work well
Add me as well.
I am one of the maintainers on bandit (python ast based security linter) which hits around 25k downloads a day, so I have a fair amount of experience in what works / does not work well
|
By
Luke A Hinds <lhinds@...>
·
#5520
·
|
|
Re: Vulnerability scanning for CNCF projects
Same, I'd be interested.
~Dave
--
~Dave
Same, I'd be interested.
~Dave
--
~Dave
|
By
Dave Zolotusky
·
#5519
·
|
|
Re: Vulnerability scanning for CNCF projects
I would be interested in that.
Justin
I would be interested in that.
Justin
|
By
Justin Cormack
·
#5518
·
|
|
Re: Vulnerability scanning for CNCF projects
If this group is interested, my team would love to present the capabilities and limitations alike of the LFX security tool project. We are working on items like creating a SBOM policy management,
If this group is interested, my team would love to present the capabilities and limitations alike of the LFX security tool project. We are working on items like creating a SBOM policy management,
|
By
Shubhra Kar
·
#5517
·
|
|
Re: [cncf-sig-security] Vulnerability scanning for CNCF projects
+1
By
alexis richardson
·
#5516
·
|
|
Re: [cncf-sig-security] Vulnerability scanning for CNCF projects
This is a great initiative that also sends a message that security is part of the core functionality.
Few suggestions:
If we can ensure CNCF projects follow Container Image authoring best practices,
This is a great initiative that also sends a message that security is part of the core functionality.
Few suggestions:
If we can ensure CNCF projects follow Container Image authoring best practices,
|
By
Gadi Naor
·
#5515
·
|
|
Re: [cncf-sig-security] Vulnerability scanning for CNCF projects
I'd be happy to join and help here.
HUGE DISCLAIMER. I work at Snyk, which is the service powering the
scans. I'm also a maintainer of Conftest as part of the Open Policy
Agent project and know a
I'd be happy to join and help here.
HUGE DISCLAIMER. I work at Snyk, which is the service powering the
scans. I'm also a maintainer of Conftest as part of the Open Policy
Agent project and know a
|
By
Gareth Rushgrove
·
#5514
·
|
|
Re: [cncf-sig-security] Vulnerability scanning for CNCF projects
Liz, this is great! Having vulnerability scanning is a good thing, but looking into the results might be too many false positives (as you pointed out) and noise. In my experience, reviewing such a
Liz, this is great! Having vulnerability scanning is a good thing, but looking into the results might be too many false positives (as you pointed out) and noise. In my experience, reviewing such a
|
By
Eli Nesterov <eli.nesterov@...>
·
#5513
·
|
|
Re: FYI: Cloud Native Security Whitepaper 2020
This is awesome ! Well done folks ...
This is awesome ! Well done folks ...
|
By
Matt Jarvis
·
#5512
·
|
|
[RESULT] Buildpacks moves to incubation
Buildpacks has been approved to move to incubation. (https://lists.cncf.io/g/cncf-toc/message/5385)
+1 Binding
9/11
Justin Cormack: https://lists.cncf.io/g/cncf-toc/message/5392
Sheng Liang:
Buildpacks has been approved to move to incubation. (https://lists.cncf.io/g/cncf-toc/message/5385)
+1 Binding
9/11
Justin Cormack: https://lists.cncf.io/g/cncf-toc/message/5392
Sheng Liang:
|
By
Amye Scavarda Perrin
·
#5511
·
|
|
Re: FYI: Cloud Native Security Whitepaper 2020
Thanks to everyone who worked so hard on this. Congratulations on shipping it, it will be very
helpful.
Justin
Thanks to everyone who worked so hard on this. Congratulations on shipping it, it will be very
helpful.
Justin
|
By
Justin Cormack
·
#5510
·
|
|
FYI: Cloud Native Security Whitepaper 2020
The CNCF Security SIG did an excellent job putting together a white paper around cloud native security:
The CNCF Security SIG did an excellent job putting together a white paper around cloud native security:
|
By
Chris Aniszczyk
·
#5509
·
|
|
Re: FYI: New Training Course on Diversity in Open Source
Let's put it as a discussion item for the next meeting and consider rolling it out in 2021
+Amye Scavarda Perrin
--
Chris Aniszczyk (@cra)
Let's put it as a discussion item for the next meeting and consider rolling it out in 2021
+Amye Scavarda Perrin
--
Chris Aniszczyk (@cra)
|
By
Chris Aniszczyk
·
#5508
·
|
|
Re: [cncf-sig-security] Vulnerability scanning for CNCF projects
" Should we have something in place for requiring projects to have a process to fix vulnerability issues (at least the serious ones)?"
We have a graduation requirement around CII badging which
" Should we have something in place for requiring projects to have a process to fix vulnerability issues (at least the serious ones)?"
We have a graduation requirement around CII badging which
|
By
Chris Aniszczyk
·
#5507
·
|
|
Re: [cncf-sig-security] Vulnerability scanning for CNCF projects
Liz,
Love this. As part of the assessments SIG-Security performs, we've begun highlighting the importance of secure development practices. The last few assessments we've begun pushing more for
Liz,
Love this. As part of the assessments SIG-Security performs, we've begun highlighting the importance of secure development practices. The last few assessments we've begun pushing more for
|
By
Emily Fox
·
#5506
·
|
|
Vulnerability scanning for CNCF projects
Hi TOC and SIG Security folks
On Friday I got a nice preview from Shubhra Kar and his team at the LF about some tools they are building to provide insights and stats for LF (and therefore CNCF)
Hi TOC and SIG Security folks
On Friday I got a nice preview from Shubhra Kar and his team at the LF about some tools they are building to provide insights and stats for LF (and therefore CNCF)
|
By
Liz Rice
·
#5505
·
|