Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Review] Dragonfly #1327

Open
8 of 15 tasks
gaius-qi opened this issue Jul 19, 2024 · 18 comments
Open
8 of 15 tasks

[Security Review] Dragonfly #1327

gaius-qi opened this issue Jul 19, 2024 · 18 comments
Assignees
Labels
triage-required Requires triage

Comments

@gaius-qi
Copy link
Contributor

gaius-qi commented Jul 19, 2024

Project Name: Dragonfly

Github URL: https://github.com/dragonflyoss/Dragonfly2

Project Security Lead: Wenbo Qi(Gaius)

CNCF project stage and issue (NA if not applicable): Incubation, applying for graduation.

Security Provider: no

  • Identify team
  • Create slack channel (#sec-assessment-dragonfly)
  • Project lead provides draft document
  • "Naive question phase" Lead Security Reviewer asks clarifying questions
  • Assign issue to security reviewers
  • Initial review
  • Presentation & discussion
  • Share draft findings with project
  • Assessment summary and doc checked into /assessments/projects/project-name (require at least 1 co-chair approval)
  • CNCF TOC presentation (if requested by TOC)
@JustinCappos
Copy link
Collaborator

@gaius-qi Okay, can you edit the info above to mention who from the dragonfly side will be the "Project Security Lead"? Please also link to the self assessment as the "Project lead provides draft document"?

@JustinCappos
Copy link
Collaborator

I am willing to be a security reviewer for this project.

I have read the security reviewer guidelines (in the past, before their link was broken... 😦 ), and have no conflicts.

@nyrahul
Copy link

nyrahul commented Jul 21, 2024

Hey @JustinCappos, I would like to volunteer with the security review (depending on eligibility).

@gaius-qi, The "security reviewer guidelines" link and the "outline" links are not working in your initial comment. I would love to go through those.

Disclosure: I have not done a CNCF project security review before. However, I am working in the security domain and have done threat modeling, security review of other projects outside of CNCF.

@JustinCappos
Copy link
Collaborator

Hey @JustinCappos, I would like to volunteer with the security review (depending on eligibility).

@gaius-qi, The "security reviewer guidelines" link and the "outline" links are not working in your initial comment. I would love to go through those.

Disclosure: I have not done a CNCF project security review before. However, I am working in the security domain and have done threat modeling, security review of other projects outside of CNCF.

Super, adding you. Would you kindly read this document and comment if you have any conflicts of interest? https://github.com/cncf/tag-security/blob/main/community/assessments/guide/security-reviewer.md (I'll try to get the link fixed.)

@nyrahul
Copy link

nyrahul commented Jul 21, 2024

I have read the security reviewer guidelines, and have no conflicts.

@krishnakv
Copy link
Contributor

Happy to volunteer. Have read the Security Reviewer Guidelines and have no conflicts.

@gaius-qi
Copy link
Contributor Author

@gaius-qi Okay, can you edit the info above to mention who from the dragonfly side will be the "Project Security Lead"? Please also link to the self assessment as the "Project lead provides draft document"?

@JustinCappos Hey! I have edited the issue to add the "Project Security Lead". Is this PR a "Project lead provides draft document"? Do you need me to provide other content? 😊

Thanks @nyrahul @krishnakv

@JustinCappos
Copy link
Collaborator

JustinCappos commented Jul 23, 2024

@gaius-qi Are you also going to be the Dragonfly POC throughout the joint review?

@mrcdb
Copy link
Member

mrcdb commented Jul 24, 2024

I'd be happy to be a security reviewer for this project. I have read the security reviewer guidelines and don't have any hard or soft conflicts.

@gaius-qi
Copy link
Contributor Author

@gaius-qi Are you also going to be the Dragonfly POC throughout the joint review?

Sure

@hubbertsmith
Copy link

I am willing to be a reviewer
I have read the guidlines
I have no conflicts of interest, neither hard nor soft
[email protected]

@mnm678
Copy link
Collaborator

mnm678 commented Jul 31, 2024

I'm willing to be the lead reviewer on this. I have no hard or soft conflicts.

@JustinCappos
Copy link
Collaborator

Okay, great! And away we go!

@mnm678 you're all set to kick this off with the naive questions phase...

@mnm678 mnm678 self-assigned this Aug 1, 2024
@mnm678
Copy link
Collaborator

mnm678 commented Aug 1, 2024

@gaius-qi Could you create a draft joint assessment for us to iterate on? Most of the content will be similar to the self assessment that you linked. Maybe in Google docs or similar format for now to allow for comments and discussion.

@nyrahul
Copy link

nyrahul commented Aug 28, 2024

@gaius-qi Could you create a draft joint assessment for us to iterate on? Most of the content will be similar to the self assessment that you linked. Maybe in Google docs or similar format for now to allow for comments and discussion.

@gaius-qi , Gentle reminder.

@JustinCappos
Copy link
Collaborator

pinging again on this... Just want to make sure we're no dropping this issue...

@gaius-qi
Copy link
Contributor Author

@gaius-qi Could you create a draft joint assessment for us to iterate on? Most of the content will be similar to the self assessment that you linked. Maybe in Google docs or similar format for now to allow for comments and discussion.

@gaius-qi , Gentle reminder.

@nyrahul @JustinCappos I'm sorry sir, I'm very busy with work recently. I will provide a draft joint assessment before September 28th. 🙏🙏🙏

@gaius-qi
Copy link
Contributor Author

@mnm678 @nyrahul @JustinCappos Hey, I have finished a draft jonit assessment.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
triage-required Requires triage
Projects
None yet
Development

No branches or pull requests

7 participants