Skip to content

Commit 38d8049

Browse files
eddie-knightmnm678brandtkeller
authored
Applied feedback to the moving-levels review template (#1387)
* Applied feedback to the moving-levels review template Signed-off-by: Eddie Knight <[email protected]> * typofix Signed-off-by: Eddie Knight <[email protected]> * linting Signed-off-by: Eddie Knight <[email protected]> * Update project-resources/moving-levels-review-template.md Co-authored-by: Marina Moore <[email protected]> Signed-off-by: Eddie Knight <[email protected]> --------- Signed-off-by: Eddie Knight <[email protected]> Co-authored-by: Marina Moore <[email protected]> Co-authored-by: Brandt Keller <[email protected]>
1 parent 1f76356 commit 38d8049

File tree

2 files changed

+30
-5
lines changed

2 files changed

+30
-5
lines changed

ci/spelling-config.json

+1
Original file line numberDiff line numberDiff line change
@@ -26,6 +26,7 @@
2626
"cisecurity",
2727
"CISO",
2828
"cloudcustodian",
29+
"CLOMonitor",
2930
"CMMC",
3031
"CNCF",
3132
"CNSC",
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
# Template for TAG recommendation to TOC
1+
# TAG recommendation to TOC
22

33
## Project Overview
44

@@ -8,13 +8,17 @@ What ecosystem adoption has the project seen?
88

99
### Past TOC Reviews
1010

11-
How has the project addressed comments from previous reviews (incubation if graduation, sandbox if incubating, etc)?
11+
If the project has undergone a previous TAG or TOC review, how has the project addressed comments from those reviews?
1212

1313
## Security Reviews
1414

1515
### TAG Security Assessments
1616

17-
Has the project completed a TAG Security Self-Assessment and/or Joint Assessment? If yes, please add a link and discuss how this has impacted their security posture.
17+
If applying for incubation, has the project completed a self-assessment? _(If not, the TAG cannot provide any recommendation to the TOC.)_
18+
19+
If applying for graduation, has the project completed a joint assessment? _(If not, the TAG cannot provide any recommendation to the TOC.)_
20+
21+
If yes to either, were there any findings or recommendations that the project has addressed or added to a roadmap? Please provide links if applicable.
1822

1923
### Security Audit
2024

@@ -24,14 +28,34 @@ Has the project completed an external security audit? If yes, how have they addr
2428

2529
### Metrics
2630

27-
Which security best practices does the project follow (for example CNCF best practices badge, OpenSSF Best Practices, CLO monitor), and how does it rate by these metrics?
31+
Which security best practices does the project follow (for example CNCF best practices badge, OpenSSF Best Practices, LFX Insights, CLOmonitor)?
32+
33+
How does it rate by these metrics? Please provide links if applicable.
2834

2935
### Static Analysis
3036

31-
Does the project perform static analysis?
37+
Does the project perform static analysis such as SAST or SCA? Please provide links if applicable.
3238

3339
## Sub-project Considerations
3440

41+
### Role of Sub-projects in the Project Ecosystem
42+
43+
Does your project have sub-projects? If so, how do they interact with the main project?
44+
45+
What is the maturity and adoption of each sub-project?
46+
47+
Please provide links to any sub-projects that are compiled into the main project.
48+
49+
Please provide links to any other sub-projects that are currently intended for end-user adoption.
50+
51+
### Security Posture of Sub-projects
52+
3553
If the project has sub-projects, how does their security posture compare to the base project?
3654

3755
## TAG Recommendation to the TOC
56+
57+
<!-- In order to form an accurate recommendation for incubation, the TAG requires the project to complete a self-assessment. -->
58+
59+
<!-- In order to form an accurate recommendation for graduation, the TAG requires the project to participate in a joint-assessment. -->
60+
61+
<!-- ... Based on these observations, the project appears to meet the expectations of a <sandbox/incubating/graduated> project. -->

0 commit comments

Comments
 (0)