Skip to content

[Security Review] Kubeflow Project  #1079

@akgraner

Description

@akgraner

Project Name: Kubeflow Project

Github URL: https://github.com/kubeflow/kubeflow/tree/master/security

Currently, we are working with Ricardo to get Kubeflow into the CNCF, we are working on going straight into incubation - cncf/toc#1042 (incubation)

Ricardo suggested that we open this issue now, since we are in the beginning stages of setting up our security team as well as our policies and procedures. I don't think we are ready for the formal security review, but we wanted to make sure you all are aware of our on-going efforts. Please let us know what else you need from us.

CNCF project stage and issue NA

Security Provider: yes (e.g. Is the primary function of the project to support the security of an integrating system?)

  • Identify team
  • Create slack channel (#sec-assess-kubeflow)
  • Project lead provides draft document - see outline
  • "Naive question phase" Lead Security Reviewer asks clarifying questions
  • Assign issue to security reviewers
  • Initial review
  • Presentation & discussion
  • Share draft findings with project
  • Assessment summary and doc checked into /assessments/projects/project-name (require at least 1 co-chair approval)
  • CNCF TOC presentation (if requested by TOC)

Metadata

Metadata

Assignees

Labels

assessmentproject security assessments (one issue per project)need-self-assessmentThe project has not yet created a self assessment

Type

No type

Projects

Status

Waiting on Project

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions