-
Notifications
You must be signed in to change notification settings - Fork 518
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Presentation] Substation Overview (CNCF Sandbox) #1356
Comments
@eddie-knight We need to schedule a date. |
Hi @jshlbrd! Here are the next openings for each time zone's community call. Do you have a preference?
|
@eddie-knight AMER 9/18 at 10 AM works for me, thanks! |
@jshlbrd you have been booked for September 18th 1000 PDT |
Great, thank you! |
TAG recommendation to TOCProject OverviewEcosystem AdoptionWhat ecosystem adoption has the project seen? Repo stats: Adoption: Shared governance model and community awareness as a reason for pursuing donation. Past TOC ReviewsApplication to Sandbox Security ReviewsTAG Security AssessmentsHas the project completed a TAG Security Self-Assessment and/or Joint Assessment? If yes, please add a link and discuss how this has impacted their security posture. No - Project is now aware that these exist. Security AuditHas the project completed an external security audit? If yes, how have they addressed the findings? A separate Brex team has conducted a review - publishing these could provide good evidence for security confidence. Team does have a process for disclosing vulnerabilities Best PracticesMetricsWhich security best practices does the project follow (for example CNCF best practices badge, OpenSSF Best Practices, CLO monitor), and how does it rate by these metrics? GitHub OSS best practices No badges displayed but could be made available. Static AnalysisDoes the project perform static analysis? Golang linting tools used for static analysis Sub-project ConsiderationsIf the project has sub-projects, how does their security posture compare to the base project? No sub-projects Plans for what could evolve as a result of donation could include separation of some efforts into sub-projects TAG Recommendation to the TOCSubstation as a toolkit is well suited to provide end users with the required tools and framework to enrich security and audit logs in a variety of architectures and scenarios. Discussion today (9/18/24) highlighted historical context, areas of opportunity, and risks involved with regards to threat surface. The criteria noted above provide opportunities for the project to evolve their project security posture and provide more value to the ecosystem. With that and the above information provided, we believe the project meets the security expectations for Sandbox. |
Title: Substation Overview (CNCF Sandbox)
Speakers:
Description: This presentation is an overview of Substation (submitted to CNCF Sandbox) and will cover its use cases, how it works (cloud native fit), history, and future.
Time: How long will the presentation take? 30 minutes (up to 45 minutes with questions).
Availability: I'm available to present during any Wednesday meeting, and as soon as the next meeting (9/4/2024).
TO DO
The text was updated successfully, but these errors were encountered: