-
Notifications
You must be signed in to change notification settings - Fork 675
Open
Description
Description
This project is a collaborative effort between the CNCF and Google's Open Source Security Team to improve security practices across various CNCF projects. The focus is identifying and addressing security vulnerabilities, integrating security tools like OSS-Fuzz, and enhancing build and release security processes. The goal is to get all CNCF projects to use scorecards (focusing on graduated/incubating projects first) and to remediate some of the findings.
Expected Outcomes
- All graduated and incubating CNCF projects using OpenSSF Scorecards to assess and enhance their security postures. Stretch goal: all (including sandbox) CNCF projects using OpenSFF Scorecards.
- Remediation of identified vulnerabilities based on scorecard findings
- Where CNCF projects are already using OpenSSF Scorecard, improved scores (remediating various risk assessments
- Integration or enhancement of fuzzing with OSS-Fuzz for CNCF projects
- Improved build/release security by automating builds and releases, added build provenance, signing, and improved reproducibility
Recommended Skills
- Security analysis
- CI/CD practices
- programming (preferably Go)
- knowledge of CNCF projects
Expected project size
large (~350 hour projects)
Mentors
- Nate Waddington (@nate-double-u, natew@cncf.io)
- Dustin Ingram (dustiningram@google.com)
vchrombie
Metadata
Metadata
Assignees
Labels
No labels
Type
Projects
Status
🆕 New