Skip to content

Kubernetes Third-Party Security Audit for 2025 (tracking issue) #104

@reylejano

Description

@reylejano

Tracking issue for the Kubernetes third-party security audit for 2025:

  • Define audit scope and provide to the Open Source Technology Improvement Fund (OSTIF)
  • OSTIF Creates RFP
    • SIG Security Third-Party Audit subproject reviews RFP
  • Vendor assessment
  • Release vendor selection
  • Create private Slack channel for vendor and subproject
  • Vendor conducts audit
    • Coordinate SME as contacts for vendor
  • Send findings to SRC
  • Findings review with SIG Security
  • Publish findings

/sig security

Metadata

Metadata

Assignees

No one assigned

    Labels

    sig/securityCategorizes an issue or PR as relevant to SIG Security.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions