-
Notifications
You must be signed in to change notification settings - Fork 534
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Karmada Project Security Self-Assessment #1166
Conversation
Updates on Languages, SBOM Link and Security File link Signed-off-by: Pranava <[email protected]> Update IR process, actors and Goals Signed-off-by: Pranava <[email protected]> Updated images Updated images of Karmada architecture and component diagram Signed-off-by: Pranava <[email protected]> Updated components diagram Updated Karmada components diagram for referring in self-assessment Signed-off-by: Pranava <[email protected]> Upload architecture Karmada architecture image uploaded for referring in the self assessment Signed-off-by: Pranava <[email protected]> Updated Security functions and features Updated Security functions and features and Changed the Threat Modeling section to Appendix Signed-off-by: Pranava <[email protected]> Updated Related Projects Updated three projects in Related Projects / Vendors subsection of Appendix Signed-off-by: Pranava <[email protected]> Updated Appendix Updated Known Issues Over Time and Case Studies Signed-off-by: Pranava <[email protected]> Update PC, SDP and Appendix Updated content in Project compliance, Secure development practices and Appendix (CII) Signed-off-by: Pranava <[email protected]> Create Languages.md Update the output of github-linguist Signed-off-by: Pranava <[email protected]> Updated document structure Updated document structure by transferring all dependencies documents under one file name docs Signed-off-by: Pranava <[email protected]> Added SBOM Added SBOM for Karmada project main branch using FOSSA-cli Signed-off-by: Pranava <[email protected]> Update Security Issue Resolution Security Issue Resolution section of the self-assessment is filled using the information available from the project Signed-off-by: Pranava <[email protected]> Update TOC -with Threat Model Signed-off-by: Pranava <[email protected]> Update TOC Signed-off-by: Pranava <[email protected]> Update TOC Signed-off-by: Pranava <[email protected]> Update Threat Modeling with STRIDE Signed-off-by: Pranava <[email protected]> Update actors Signed-off-by: Pranava <[email protected]> Updated Non-Goals General - TBD Security - Added Signed-off-by: Pranava <[email protected]> Update Goals Updates General and Security goals Signed-off-by: Pranava <[email protected]> Update to Actors Signed-off-by: Pranava <[email protected]> Updated Actors and Actions Initial update on actor and Actions Signed-off-by: Pranava <[email protected]> updated background - Update self-assessment.md updated background Signed-off-by: Pranava <[email protected]> Update self-assessment.md overview Signed-off-by: Pranava <[email protected]> Update self-assessment.md Update document info Signed-off-by: Pranava <[email protected]> Create self-assessment.md self-assessment template from the tag-security is used to start Signed-off-by: Pranava <[email protected]>
✅ Deploy Preview for tag-security canceled.
|
a57a6f2
to
9fcc607
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for the PR @Rana-KV and team, appreciate the efforts.
I have completed first pass of review and left a few comments on section that needs your attention. Please feel free to reach out here or on slack for any questions and clarifications.
@Rana-KV Please update the PR per the outstanding commands. |
Updated SBOM info as per the suggestion in the review Signed-off-by: Pranava <[email protected]>
The initial document was missing default and optional configuration information, the link has been update now. Signed-off-by: Pranava <[email protected]>
Signed-off-by: Pranava <[email protected]>
As per suggestion, removed the threat modeling content from self assessment and made it into a separate document. Linked the document in the Security Self-Assessment. Signed-off-by: Pranava <[email protected]>
Signed-off-by: Pranava <[email protected]>
Signed-off-by: Pranava <[email protected]>
Signed-off-by: Raga <[email protected]>
Signed-off-by: Raga <[email protected]>
Signed-off-by: Raga <[email protected]>
Signed-off-by: Raga <[email protected]>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks solid. We should merge!
Created and added first draft for Karmada Project Security Self-Assessment.