Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Presentation] Substation Overview (CNCF Sandbox) #1356

Closed
1 of 4 tasks
jshlbrd opened this issue Aug 29, 2024 · 6 comments
Closed
1 of 4 tasks

[Presentation] Substation Overview (CNCF Sandbox) #1356

jshlbrd opened this issue Aug 29, 2024 · 6 comments
Labels
triage-required Requires triage usecase-presentation Label for usecase related presentations

Comments

@jshlbrd
Copy link

jshlbrd commented Aug 29, 2024

Title: Substation Overview (CNCF Sandbox)

Speakers:

Description: This presentation is an overview of Substation (submitted to CNCF Sandbox) and will cover its use cases, how it works (cloud native fit), history, and future.

Time: How long will the presentation take? 30 minutes (up to 45 minutes with questions).

Availability: I'm available to present during any Wednesday meeting, and as soon as the next meeting (9/4/2024).

TO DO

@jshlbrd jshlbrd added triage-required Requires triage usecase-presentation Label for usecase related presentations labels Aug 29, 2024
@y-tabata
Copy link
Contributor

y-tabata commented Sep 4, 2024

@eddie-knight We need to schedule a date.

@eddie-knight
Copy link
Collaborator

eddie-knight commented Sep 7, 2024

Hi @jshlbrd!

Here are the next openings for each time zone's community call. Do you have a preference?

@jshlbrd
Copy link
Author

jshlbrd commented Sep 7, 2024

@eddie-knight AMER 9/18 at 10 AM works for me, thanks!

@mrcdb
Copy link
Member

mrcdb commented Sep 9, 2024

@jshlbrd you have been booked for September 18th 1000 PDT

@jshlbrd
Copy link
Author

jshlbrd commented Sep 9, 2024

@jshlbrd you have been booked for September 18th 1000 PDT

Great, thank you!

@brandtkeller
Copy link
Collaborator

brandtkeller commented Sep 19, 2024

TAG recommendation to TOC

Project Overview

Ecosystem Adoption

What ecosystem adoption has the project seen?

Repo stats:
317 stars
8 contributors
179 commits @ main
38 Releases

Adoption:
Brex in production
Other companies (Approx 3) using in production

Shared governance model and community awareness as a reason for pursuing donation.

Past TOC Reviews

Application to Sandbox

Security Reviews

TAG Security Assessments

Has the project completed a TAG Security Self-Assessment and/or Joint Assessment? If yes, please add a link and discuss how this has impacted their security posture.

No - Project is now aware that these exist.

Security Audit

Has the project completed an external security audit? If yes, how have they addressed the findings?

A separate Brex team has conducted a review - publishing these could provide good evidence for security confidence.

Team does have a process for disclosing vulnerabilities

Best Practices

Metrics

Which security best practices does the project follow (for example CNCF best practices badge, OpenSSF Best Practices, CLO monitor), and how does it rate by these metrics?

GitHub OSS best practices

No badges displayed but could be made available.

Static Analysis

Does the project perform static analysis?

Golang linting tools used for static analysis

Sub-project Considerations

If the project has sub-projects, how does their security posture compare to the base project?

No sub-projects

Plans for what could evolve as a result of donation could include separation of some efforts into sub-projects

TAG Recommendation to the TOC

Substation as a toolkit is well suited to provide end users with the required tools and framework to enrich security and audit logs in a variety of architectures and scenarios. Discussion today (9/18/24) highlighted historical context, areas of opportunity, and risks involved with regards to threat surface. The criteria noted above provide opportunities for the project to evolve their project security posture and provide more value to the ecosystem.

With that and the above information provided, we believe the project meets the security expectations for Sandbox.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
triage-required Requires triage usecase-presentation Label for usecase related presentations
Projects
None yet
Development

No branches or pull requests

5 participants