Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Review] Hexa Policy Orchestration #955

Closed
3 of 15 tasks
ggebel opened this issue Jul 13, 2022 · 12 comments
Closed
3 of 15 tasks

[Security Review] Hexa Policy Orchestration #955

ggebel opened this issue Jul 13, 2022 · 12 comments
Assignees
Labels
assessment project security assessments (one issue per project)

Comments

@ggebel
Copy link

ggebel commented Jul 13, 2022

Project Name: Hexa Policy Orchestration

Github URL: https://github.com/hexa-org

CNCF project stage and issue (NA if not applicable): NA, pre-sandbox submission

Security Provider: yes/no (e.g. Is the primary function of the project to support the security of an integrating system?) Yes

  • Identify team
  • Create slack channel (e.g. #sec-assess-projectname)
  • Project lead provides draft document - self assessment
  • "Naive question phase" Lead Security Reviewer asks clarifying questions
  • Assign issue to security reviewers
  • Initial review
  • Presentation & discussion
  • Share draft findings with project
  • Assessment summary and doc checked into /assessments/projects/project-name (require at least 1 co-chair approval)
  • CNCF TOC presentation (if requested by TOC)
@ggebel
Copy link
Author

ggebel commented Jul 21, 2022

First draft of self assessment
Hexa self assessment.pdf

@stale
Copy link

stale bot commented Sep 21, 2022

This issue has been automatically marked as inactive because it has not had recent activity.

@stale stale bot added the inactive No activity on issue/PR label Sep 21, 2022
@anvega anvega added the assessment project security assessments (one issue per project) label Jun 21, 2023
@stale stale bot removed the inactive No activity on issue/PR label Jun 21, 2023
@JustinCappos JustinCappos self-assigned this Jul 7, 2023
@JustinCappos
Copy link
Collaborator

Thank you for sending this self assessment. Can you give a copy in Google Doc format so it is easy for us to comment on it?

Also, given the project is pre-sandbox, it may take a little time to get a team together from our side to assess this. Please feel free to ping us to ask about this if you do not hear back in a reasonable timeframe.

@JustinCappos JustinCappos removed the triage-required Requires triage label Jul 7, 2023
@ggebel
Copy link
Author

ggebel commented Jul 7, 2023

@JustinCappos
Copy link
Collaborator

Okay, thanks!

@ggebel Will you act as the project security lead?

@ggebel
Copy link
Author

ggebel commented Jul 10, 2023

Yes, @JustinCappos , I will act as security lead and bring in others as necessary

@JustinCappos
Copy link
Collaborator

Yes, @JustinCappos , I will act as security lead and bring in others as necessary

Okay, thanks. I added you above.

@stale
Copy link

stale bot commented Sep 17, 2023

This issue has been automatically marked as inactive because it has not had recent activity.

@stale stale bot added the inactive No activity on issue/PR label Sep 17, 2023
@JustinCappos
Copy link
Collaborator

I'm marking myself as lead reviewer. (I'm open to playing a different role if someone else wants to volunteer.)

I'll try to recruit other reviewers in the meeting this week. @ggebel , do you have cycles in the next month or so?

@stale stale bot removed the inactive No activity on issue/PR label Sep 17, 2023
@ggebel
Copy link
Author

ggebel commented Sep 18, 2023

Hi @JustinCappos - I should be able to make the call this week. Yes, I can make some time for discussions in the next month+. However, note that we are making some changes to the next version so I'm not sure if you want to wait for that work to complete or to get the first assessment completed sooner

@JustinCappos
Copy link
Collaborator

I think that waiting may be better. Just give us a heads up when the next version is out and the self assessment is being revised. I can get a team together then.

@eddie-knight
Copy link
Collaborator

Closing this for now

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
assessment project security assessments (one issue per project)
Projects
Status: Waiting on Project
Development

No branches or pull requests

4 participants