You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
@@ -8,13 +8,17 @@ What ecosystem adoption has the project seen?
8
8
9
9
### Past TOC Reviews
10
10
11
-
How has the project addressed comments from previous reviews (incubation if graduation, sandbox if incubating, etc)?
11
+
If the project has undergone a previous TAG or TOC review, how has the project addressed comments from those reviews?
12
12
13
13
## Security Reviews
14
14
15
15
### TAG Security Assessments
16
16
17
-
Has the project completed a TAG Security Self-Assessment and/or Joint Assessment? If yes, please add a link and discuss how this has impacted their security posture.
17
+
If applying for incubation, has the project completed a self-assessment? _(If not, the TAG cannot provide any recommendation to the TOC.)_
18
+
19
+
If applying for graduation, has the project completed a joint assessment? _(If not, the TAG cannot provide any recommendation to the TOC.)_
20
+
21
+
If yes to either, were there any findings or recommendations that the project has addressed or added to a roadmap? Please provide links if applicable.
18
22
19
23
### Security Audit
20
24
@@ -24,14 +28,34 @@ Has the project completed an external security audit? If yes, how have they addr
24
28
25
29
### Metrics
26
30
27
-
Which security best practices does the project follow (for example CNCF best practices badge, OpenSSF Best Practices, CLO monitor), and how does it rate by these metrics?
31
+
Which security best practices does the project follow (for example CNCF best practices badge, OpenSSF Best Practices, LFX Insights, CLOmonitor)?
32
+
33
+
How does it rate by these metrics? Please provide links if applicable.
28
34
29
35
### Static Analysis
30
36
31
-
Does the project perform static analysis?
37
+
Does the project perform static analysis such as SAST or SCA? Please provide links if applicable.
32
38
33
39
## Sub-project Considerations
34
40
41
+
### Role of Sub-projects in the Project Ecosystem
42
+
43
+
Does your project have sub-projects? If so, how do they interact with the main project?
44
+
45
+
What is the maturity and adoption of each sub-project?
46
+
47
+
Please provide links to any sub-projects that are compiled into the main project.
48
+
49
+
Please provide links to any other sub-projects that are currently intended for end-user adoption.
50
+
51
+
### Security Posture of Sub-projects
52
+
35
53
If the project has sub-projects, how does their security posture compare to the base project?
36
54
37
55
## TAG Recommendation to the TOC
56
+
57
+
<!-- In order to form an accurate recommendation for incubation, the TAG requires the project to complete a self-assessment. -->
58
+
59
+
<!-- In order to form an accurate recommendation for graduation, the TAG requires the project to participate in a joint-assessment. -->
60
+
61
+
<!-- ... Based on these observations, the project appears to meet the expectations of a <sandbox/incubating/graduated> project. -->
0 commit comments