Skip to content

CNCF and Google Open Source Security Team GSoC Collaboration - Enhancing Security Across CNCF Ecosystem #1196

@nate-double-u

Description

@nate-double-u

Description

This project is a collaborative effort between the CNCF and Google's Open Source Security Team to improve security practices across various CNCF projects. The focus is identifying and addressing security vulnerabilities, integrating security tools like OSS-Fuzz, and enhancing build and release security processes. The goal is to get all CNCF projects to use scorecards (focusing on graduated/incubating projects first) and to remediate some of the findings.

Expected Outcomes

  • All graduated and incubating CNCF projects using OpenSSF Scorecards to assess and enhance their security postures. Stretch goal: all (including sandbox) CNCF projects using OpenSFF Scorecards.
  • Integration or enhancement of fuzzing with OSS-Fuzz for CNCF projects
  • Improved build/release security by automating builds and releases, added build provenance, signing, and improved reproducibility

Recommended Skills

  • Security analysis
  • CI/CD practices
  • programming (preferably Go)
  • knowledge of CNCF projects

Expected project size

large (~350 hour projects)

Mentors

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Status

    🆕 New

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions