Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[CNCF] CII Best Practices Badge #12

Closed
1 task
dcmiddle opened this issue Mar 14, 2022 · 9 comments
Closed
1 task

[CNCF] CII Best Practices Badge #12

dcmiddle opened this issue Mar 14, 2022 · 9 comments
Assignees
Labels
cncf-onboarding security-badge OpenSSF Best Practices Badge

Comments

@dcmiddle
Copy link
Member

Parts of the CNCF onboarding issue tracked by this issue

This is the list of all bullet points from the CNCF onboarding issue that this issue will track:

@dcmiddle
Copy link
Member Author

The CII Best Practices badge is meant to help maintainers be conscious if not fulfill security best practices.
It needs to be started as a team in a live discussion - probably one of our thursday sessions. Typically it takes more than 1 full session to complete. We aren't required to immediately complete the badge (which could take months to satisfy certain criteria) but we do need to get a solid start. This probably means consuming the bulk of one of the next ~3 meetings in order to make the 1 month CNCF deadline.

@ariel-adam ariel-adam moved this from In progress (have an owner) to Backlog (no owner) in COCO CNCF Onboarding Mar 15, 2022
@dcmiddle dcmiddle moved this from Backlog (no owner) to In progress (have an owner) in COCO CNCF Onboarding Mar 17, 2022
@dcmiddle dcmiddle moved this from In progress (have an owner) to Backlog (no owner) in COCO CNCF Onboarding Mar 17, 2022
@dcmiddle
Copy link
Member Author

I initiated the badge process. I will fill in some of the boilerplate material directly, but most of this should be discussed in the community meeting.
https://bestpractices.coreinfrastructure.org/en/projects/5719

@dcmiddle dcmiddle moved this from Backlog (no owner) to In progress (have an owner) in COCO CNCF Onboarding Mar 18, 2022
@ariel-adam ariel-adam moved this from In progress (have an owner) to Discussion topic in COCO CNCF Onboarding Mar 21, 2022
@fitzthum
Copy link
Member

Planning to discuss during community meeting on the 31st. As you say, we definitely won't be able to complete all of the requirements before onboarding, but these seem like very thorough guidelines that will benefit the project and overlap significantly with requirements for incubation.

@dcmiddle
Copy link
Member Author

We could also do it 2022/03/24.

@ariel-adam
Copy link
Member

Dan, what remains to do on this issue?

@dcmiddle dcmiddle added the security-badge OpenSSF Best Practices Badge label Apr 11, 2022
@dcmiddle
Copy link
Member Author

We have met the letter of the requirement by starting the badging process. However, to fulfill the spirit of the requirement I will be adding issues which cover the unmet portions of the badging checklist.
I created a security-badge label for those issues.
Once those issues are created and socialized with the community we can move this onboarding issue to complete.

@dcmiddle
Copy link
Member Author

@dcmiddle
Copy link
Member Author

The onboarding task requirements are complete...

@dcmiddle dcmiddle moved this from Discussion topic to Done in COCO CNCF Onboarding Apr 14, 2022
@ariel-adam
Copy link
Member

@dcmiddle is this issue still relevant or can be closed?
If it's still relevant to what release do you think we should map it to (mid-November, end-December, mid-February etc...)?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
cncf-onboarding security-badge OpenSSF Best Practices Badge
Projects
Development

No branches or pull requests

3 participants