Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

private-distributors-list: add DaoCloud #180

Open
1 task
pacoxu opened this issue May 23, 2023 · 11 comments · May be fixed by kubernetes/k8s.io#5361
Open
1 task

private-distributors-list: add DaoCloud #180

pacoxu opened this issue May 23, 2023 · 11 comments · May be fixed by kubernetes/k8s.io#5361
Assignees

Comments

@pacoxu
Copy link
Member

pacoxu commented May 23, 2023

Actively monitored security email alias for our project: kubernetes-security@daocloud.io

1. Be an actively maintained and CNCF-certified distribution of Kubernetes components.
DaoCloud is in the list of https://www.cncf.io/certification/software-conformance/

  • and we also maintain an opensource project kubean(which is a kubespray operator). It is listed in Certified Kubernetes - Installer part of the page above.

2. Have a user base not limited to your own organization.
Yes

3. Have a publicly verifiable track record up to the present day of fixing security issues.

4. Not be a downstream or rebuild of another distribution.
No.

5. Be a participant and active contributor in the community.
https://k8s.devstats.cncf.io/d/9/companies-table?orgId=1
DaoCloud ranks top 10 in kubernetes community contributions in history, and top 5 if only counting recent 3 years.

Some of the active contributors from DaoCloud in the community:

Besides code contributions, we also organized several KCD and KCS in China including KCS China 2023, KCD Beijing 2021&2023, KCD Shanghai 2021&2024, KCD Chengdu 2022 and KCD Shenzhen 2023.

  • @Iceber who is CNCF ambassador and containerd/clusterpedia/wasmcloud maintainer, lead the organization of recent several KCDs.
    Most of the SIG maintainer talks in KubeCon China 2023 are by DaoClouder, including SIG-Scheduling, SIG-Node, SIG-Instrumentation, Kubespray, KWOK sessions.

BTW, we also try to maintainer kube lts version in https://github.com/klts-io/kubernetes-lts for an extended period, and it is open-source and only focus on high value CVEs currently.

6. Accept the Embargo Policy.

Yes.

7. Be willing to contribute back.

yes

8. Have someone already on the list vouch for the person requesting membership on behalf of your distribution.
VMware and Microsoft below.

More information can be found in https://github.com/DaoCloud, https://www.daocloud.io/en/ and https://docs.daocloud.io/en/.

@pacoxu
Copy link
Member Author

pacoxu commented May 26, 2023

/cc @puerco @ritazh

@neolit123
Copy link
Member

DaoCloud ranks top 10 in kubernetes community contributions.

+1 to be added

@neolit123 (VMware)

@ritazh
Copy link
Member

ritazh commented May 31, 2023

+1

@ritazh (Microsoft)

@pacoxu
Copy link
Member Author

pacoxu commented Aug 28, 2023

ack

@enj enj self-assigned this Aug 29, 2023
@pacoxu
Copy link
Member Author

pacoxu commented Nov 17, 2023

@kubernetes/security-response-committee any update?

@enj
Copy link
Member

enj commented Nov 17, 2023

@kubernetes/security-response-committee any update?

I haven't forgotten, just haven't had time to update distributor requirements.

@pacoxu
Copy link
Member Author

pacoxu commented Jan 29, 2024

Updated some new approvers/reviewers in Kubernetes Community from DaoCloud.

@pacoxu
Copy link
Member Author

pacoxu commented Feb 1, 2024

@kubernetes/security-response-committee ACK

@k8s-triage-robot
Copy link

The Kubernetes project currently lacks enough contributors to adequately respond to all issues.

This bot triages un-triaged issues according to the following rules:

  • After 90d of inactivity, lifecycle/stale is applied
  • After 30d of inactivity since lifecycle/stale was applied, lifecycle/rotten is applied
  • After 30d of inactivity since lifecycle/rotten was applied, the issue is closed

You can:

  • Mark this issue as fresh with /remove-lifecycle stale
  • Close this issue with /close
  • Offer to help out with Issue Triage

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle stale

@k8s-ci-robot k8s-ci-robot added the lifecycle/stale Denotes an issue or PR has remained open with no activity and has become stale. label May 1, 2024
@pacoxu
Copy link
Member Author

pacoxu commented May 1, 2024

/remove-lifecycle stale
still valid in progress

@k8s-ci-robot k8s-ci-robot removed the lifecycle/stale Denotes an issue or PR has remained open with no activity and has become stale. label May 1, 2024
@pacoxu
Copy link
Member Author

pacoxu commented May 9, 2024

I haven't forgotten, just haven't had time to update distributor requirements.

@enj do we have any new requirements for being in the private distributor list? So I can evaluate them and add them to our action items.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

6 participants