|
Re: security & CNCF projects
I've realised that one reason the results look so damning for the projects is that they are the sum of vulnerabilities found over a period of time (and an arbitrary period of time at that). For
I've realised that one reason the results look so damning for the projects is that they are the sum of vulnerabilities found over a period of time (and an arbitrary period of time at that). For
|
By
Liz Rice
·
#5673
·
|
|
Re: security & CNCF projects
I understand this is Beta
I believe all of the CNCF community should have equal access.
I understand this is Beta
I believe all of the CNCF community should have equal access.
|
By
alexis richardson
·
#5672
·
|
|
Re: security & CNCF projects
Alexis, the tool is freely available just like a variety of other security tools that CNCF projects use, from LFX Security (white labeled Snyk), Snyk, FOSSA, CodeQL, WhiteSource etc, lots of great
Alexis, the tool is freely available just like a variety of other security tools that CNCF projects use, from LFX Security (white labeled Snyk), Snyk, FOSSA, CodeQL, WhiteSource etc, lots of great
|
By
Chris Aniszczyk
·
#5671
·
|
|
Re: security & CNCF projects
I strongly disagree Chris, this is a great resource that all should be aware of.
Now that we don’t have FPs, can we just publish the data? Please do not assume that end users will not run their own
I strongly disagree Chris, this is a great resource that all should be aware of.
Now that we don’t have FPs, can we just publish the data? Please do not assume that end users will not run their own
|
By
alexis richardson
·
#5670
·
|
|
Re: security & CNCF projects
+1 to what Liz said here, this should be opt-in for project maintainers like any tool
Can we please just leave this as a per project decision as any other tool as we decided last time this came up,
+1 to what Liz said here, this should be opt-in for project maintainers like any tool
Can we please just leave this as a per project decision as any other tool as we decided last time this came up,
|
By
Chris Aniszczyk
·
#5669
·
|
|
Re: security & CNCF projects
The scan data from Snyk right now is fairly clean as they curate and weed out false positives proactively. In the tool, we do have flags on the bugs to dismiss it (in case it's still a false
The scan data from Snyk right now is fairly clean as they curate and weed out false positives proactively. In the tool, we do have flags on the bugs to dismiss it (in case it's still a false
|
By
Shubhra Kar
·
#5668
·
|
|
Re: security & CNCF projects
I have an idea that there were concerns about making the data publicly available because of false positives, and the worry that if projects appear (incorrectly) to be unsafe that will impede adoption.
I have an idea that there were concerns about making the data publicly available because of false positives, and the worry that if projects appear (incorrectly) to be unsafe that will impede adoption.
|
By
Liz Rice
·
#5667
·
|
|
Re: security & CNCF projects
Idea: It would be cool if all CNCF projects had the same metadata for representing "maintainers".
If that was standardized, some tool could ingest and compare against LFIDs.
-- Stephen
Idea: It would be cool if all CNCF projects had the same metadata for representing "maintainers".
If that was standardized, some tool could ingest and compare against LFIDs.
-- Stephen
|
By
Stephen Augustus
·
#5666
·
|
|
Re: security & CNCF projects
Essentially we want them to create LFIDs to grant access.
Shubhra
Essentially we want them to create LFIDs to grant access.
Shubhra
|
By
Shubhra Kar
·
#5665
·
|
|
Re: security & CNCF projects
Thanks Stephen.
We have granted access to given access to stefan@....
We are unable to find accounts forhidde@... and michael@... .
Regards,
Vasu
From:Stephen Augustus
Thanks Stephen.
We have granted access to given access to stefan@....
We are unable to find accounts forhidde@... and michael@... .
Regards,
Vasu
From:Stephen Augustus
|
By
Vasu Naidu <vnaidu@...>
·
#5664
·
|
|
Re: security & CNCF projects
Hi Alexis,
You should have access to the security reports of the flux project. Please let me know if you have any questions.
Hi Alexis,
You should have access to the security reports of the flux project. Please let me know if you have any questions.
|
By
Vasu Naidu <vnaidu@...>
·
#5663
·
|
|
Re: security & CNCF projects
As I understand it, https://maintainers.cncf.io/ holds the aggregate maintainers for CNCF project.
For flux, specifically: https://github.com/fluxcd/flux/blob/master/MAINTAINERS
-- Stephen
As I understand it, https://maintainers.cncf.io/ holds the aggregate maintainers for CNCF project.
For flux, specifically: https://github.com/fluxcd/flux/blob/master/MAINTAINERS
-- Stephen
|
By
Stephen Augustus
·
#5662
·
|
|
Re: security & CNCF projects
I would suggest we add access for all the maintainers of the project and anyone on the governance committees (example TSCs).
Do you maintain a maintainers.md file or better for us to just scan the
I would suggest we add access for all the maintainers of the project and anyone on the governance committees (example TSCs).
Do you maintain a maintainers.md file or better for us to just scan the
|
By
Shubhra Kar
·
#5661
·
|
|
Re: security & CNCF projects
thanks, how do I share these with the flux maintainers and community
thanks, how do I share these with the flux maintainers and community
|
By
alexis richardson
·
#5660
·
|
|
Re: security & CNCF projects
Yes, please.
To your general point -- I have a view that if Snyk (or similar) offers a free scanning service to CNCF projects, then the community should benefit. These are completely standard
Yes, please.
To your general point -- I have a view that if Snyk (or similar) offers a free scanning service to CNCF projects, then the community should benefit. These are completely standard
|
By
alexis richardson
·
#5659
·
|
|
Re: security & CNCF projects
Jim,
We are looking into, let me get back to you with an update.
Regards,
Vasu
---
Sr. Director, Head Of Engineering
Cell: 1.408.420.0404
Slack:@Vasu
From:St Leger, Jim
Jim,
We are looking into, let me get back to you with an update.
Regards,
Vasu
---
Sr. Director, Head Of Engineering
Cell: 1.408.420.0404
Slack:@Vasu
From:St Leger, Jim
|
By
Vasu Naidu <vnaidu@...>
·
#5658
·
|
|
Re: security & CNCF projects
That depends on your viewpoint, the maintainers ideally should make that call per project based on whatever security process they have in place for the project. You can have a view that maintainers
That depends on your viewpoint, the maintainers ideally should make that call per project based on whatever security process they have in place for the project. You can have a view that maintainers
|
By
Chris Aniszczyk
·
#5657
·
|
|
Re: security & CNCF projects
I see. Well, I'm not.
This info should be open to all, without any barriers whatsoever
I see. Well, I'm not.
This info should be open to all, without any barriers whatsoever
|
By
alexis richardson
·
#5656
·
|
|
Re: security & CNCF projects
I think what Chris means is that if you are already scanning with Snyk, then you won't see anything different in the LFX feed.
I think what Chris means is that if you are already scanning with Snyk, then you won't see anything different in the LFX feed.
|
By
Matt Jarvis
·
#5655
·
|
|
Re: Agenda for TOC Meeting for 2/16
Apologies - will miss TOC liaison discussion today.
No electricity or water in my area. No/limited cellular. Hoping this message catches a signal before tomorrow’s call.
-Lee
Apologies - will miss TOC liaison discussion today.
No electricity or water in my area. No/limited cellular. Hoping this message catches a signal before tomorrow’s call.
-Lee
|
By
Lee Calcote
·
#5654
·
|