-
Notifications
You must be signed in to change notification settings - Fork 236
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Applied for security audit #964
Comments
@evankanderson Do you have access now with your knative.team email to service desk? |
Thank you @evankanderson it looks like CNFC got you in contact with the auditor
Let us know how it goes once you have more info. |
I chatted with Amir on Tuesday, and we filled out an audit questionnaire together: https://docs.google.com/document/d/1YaEK5zWmOk1G_eFuiJCPYGm7nWc2l97eBK3wINYNJTE/edit Sometime (possibly post-Kubecon), we'll probably put together two RFPs: ServingA standard security audit, taking into account the in-progress encryption of KIngress -> activator -> queue_proxy path. EventingProbably a more protocol-focused audit this time, focusing on modeling necessary controls and mitigations, probably including:
|
@evankanderson any updates on this front? |
Hi everyone! I have emailed @evankanderson a few times since July about this but have not heard back. We are ready and happy to continue the conversation and help knative get their security audit done as we do with many cncf projects! |
Sorry, this got dropped under a bunch of vacation and acquisition traffic -- I'll dig out the emails and respond today. |
/close We now have 2 audits:
Closing this as done |
/close |
@aliok: Closing this issue. In response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
Applied for CNCF security audit
Having a security audit performed by CNCF contractor for Knative is a requirement for CNCF project graduation.
I was advised by @caniszczyk to go ahead and open a service ticket now, since there is a large backlog for the Security contractor
cc @evankanderson
The text was updated successfully, but these errors were encountered: