-
Notifications
You must be signed in to change notification settings - Fork 73
Closed as not planned
Labels
area/alizerEnhancement or issue related to the alizer repoEnhancement or issue related to the alizer repoarea/apiEnhancement or issue related to the api/devfile specificationEnhancement or issue related to the api/devfile specificationarea/landing-pageIssues with the Landing PageIssues with the Landing Pagearea/libraryCommon devfile library for interacting with devfilesCommon devfile library for interacting with devfilesarea/registryDevfile registry for stacks and infrastructureDevfile registry for stacks and infrastructurekind/epicA high level requirement that can/should be split into smaller issuesA high level requirement that can/should be split into smaller issueskind/user-storyUser story for new enhancementUser story for new enhancementlifecycle/rottenRotten items. These items have been stale for 60 days and are now closed.Rotten items. These items have been stale for 60 days and are now closed.lifecycle/staleStale items. These items have not been updated for 90 days.Stale items. These items have not been updated for 90 days.
Description
/kind user-story
/kind epic
Which area this user story is related to?
/area api
/area library
/area registry
/area alizer
/area landing-page
User Story
As part of the CNCF Defender EPIC it is recommended to add a security-policy. As part of the security policy it is also recommended to add:
- A security threat model, as part of the
security-artifactsinside theSECURITY-INSIGHTS.yamlof each repo. The thread model can be the same for every devfile org repo. An example threat model is here: https://github.com/cncf/financial-user-group/blob/main/projects/k8s-threat-model/README.md - A vulnerability reporting process, which about how to report properly a security issue.
Both the threat model and the vulnerability report process can be part of a more generic Security.md file which also can define additional policies and procedures followed by the devfile org.
Acceptance Criteria
Metadata
Metadata
Assignees
Labels
area/alizerEnhancement or issue related to the alizer repoEnhancement or issue related to the alizer repoarea/apiEnhancement or issue related to the api/devfile specificationEnhancement or issue related to the api/devfile specificationarea/landing-pageIssues with the Landing PageIssues with the Landing Pagearea/libraryCommon devfile library for interacting with devfilesCommon devfile library for interacting with devfilesarea/registryDevfile registry for stacks and infrastructureDevfile registry for stacks and infrastructurekind/epicA high level requirement that can/should be split into smaller issuesA high level requirement that can/should be split into smaller issueskind/user-storyUser story for new enhancementUser story for new enhancementlifecycle/rottenRotten items. These items have been stale for 60 days and are now closed.Rotten items. These items have been stale for 60 days and are now closed.lifecycle/staleStale items. These items have not been updated for 90 days.Stale items. These items have not been updated for 90 days.
Type
Projects
Status
Done ✅