Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Cortex Project Security Self-Assessment - Security Pals #1188

Merged
merged 28 commits into from
Jan 25, 2024

Conversation

heydc7
Copy link
Contributor

@heydc7 heydc7 commented Dec 7, 2023

Created and added the first draft of Cortex Project Security Self-Assessment. Please feel free to share your thoughts on the security self-assessment.

Contributors: Dhanraj Chavan, Raiya Haque, Abdul Alhazmi, Sushanth Ravipalli

Signed-off-by: Dhanraj Chavan <39642060+heydc7@users.noreply.github.com>
Signed-off-by: Dhanraj Chavan <39642060+heydc7@users.noreply.github.com>
Signed-off-by: Dhanraj Chavan <39642060+heydc7@users.noreply.github.com>
Signed-off-by: Dhanraj Chavan <39642060+heydc7@users.noreply.github.com>
Signed-off-by: Dhanraj Chavan <39642060+heydc7@users.noreply.github.com>
Signed-off-by: Dhanraj Chavan <39642060+heydc7@users.noreply.github.com>
Copy link

netlify bot commented Dec 7, 2023

Deploy Preview for tag-security canceled.

Name Link
🔨 Latest commit 9042939
🔍 Latest deploy log https://app.netlify.com/sites/tag-security/deploys/65b2af8101c83b00086e3624

@heydc7 heydc7 force-pushed the main branch 3 times, most recently from af1ddaa to fc89215 Compare December 8, 2023 02:03
@eddie-knight

This comment was marked as resolved.

@eddie-knight

This comment was marked as resolved.

Signed-off-by: Dhanraj Chavan <39642060+heydc7@users.noreply.github.com>
Co-authored-by: Raiya Haque <raiya811@gmail.com>
Co-authored-by: Abdul Alhazmi <Aa11533@nyu.edu>
Co-authored-by: Sushanth Ravipalli <sushanth3120@gmail.com>

@raiyahaque @abkzmii @sushanth3120
@heydc7
Copy link
Contributor Author

heydc7 commented Dec 8, 2023

Sure, I'll remove SBOM from this assessment. I have fixed the DCO check.

Signed-off-by: Dhanraj Chavan <dc6707914@gmail.com>
Co-authored-by: Raiya Haque <raiya811@gmail.com>
Co-authored-by: Abdul Alhazmi <Aa11533@nyu.edu>
Co-authored-by: Sushanth Ravipalli <sushanth3120@gmail.com>

Signed-off-by: Dhanraj Chavan <39642060+heydc7@users.noreply.github.com>
@heydc7
Copy link
Contributor Author

heydc7 commented Dec 8, 2023

Done. Removed SBOM ✅

@heydc7
Copy link
Contributor Author

heydc7 commented Dec 9, 2023

Ok, we will do it.

@heydc7 heydc7 changed the title Cortex Project Security Self-Assessment Cortex Project Security Self-Assessment - Security Pals Dec 9, 2023
heydc7 and others added 2 commits December 9, 2023 14:27
Co-authored-by: Eddie Knight <iv.eddieknight@gmail.com>
Signed-off-by: Dhanraj Chavan <39642060+heydc7@users.noreply.github.com>
Signed-off-by: Dhanraj Chavan <dc6707914@gmail.com>
Co-authored-by: Raiya Haque <raiya811@gmail.com>
Co-authored-by: Abdul Alhazmi <Aa11533@nyu.edu>
Co-authored-by: Sushanth Ravipalli <sushanth3120@gmail.com>

Signed-off-by: Dhanraj Chavan <39642060+heydc7@users.noreply.github.com>
@heydc7
Copy link
Contributor Author

heydc7 commented Dec 9, 2023

Done ✅

Copy link
Contributor

@ragashreeshekar ragashreeshekar left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the PR @heydc7 and team, appreciate the efforts.
I have completed first pass of review. Please feel free to reach out here or on slack for any questions and clarifications.

Along with addressing the comments, kindly update the PR branch with the latest content in the repo as this branch is out-of-date with the base branch.

assessments/projects/cortex/sbom.json Outdated Show resolved Hide resolved
assessments/projects/cortex/self-assessment.md Outdated Show resolved Hide resolved
assessments/projects/cortex/self-assessment.md Outdated Show resolved Hide resolved
assessments/projects/cortex/self-assessment.md Outdated Show resolved Hide resolved
Signed-off-by: Dhanraj Chavan <39642060+heydc7@users.noreply.github.com>
Signed-off-by: Dhanraj Chavan <39642060+heydc7@users.noreply.github.com>
Signed-off-by: Dhanraj Chavan <39642060+heydc7@users.noreply.github.com>
Signed-off-by: Dhanraj Chavan <39642060+heydc7@users.noreply.github.com>
@heydc7
Copy link
Contributor Author

heydc7 commented Dec 10, 2023

PR Branch updated

Signed-off-by: Dhanraj Chavan <39642060+heydc7@users.noreply.github.com>
Signed-off-by: Dhanraj Chavan <39642060+heydc7@users.noreply.github.com>
@heydc7
Copy link
Contributor Author

heydc7 commented Dec 11, 2023

All changes are done ✅

heydc7 and others added 2 commits December 11, 2023 20:12
Co-authored-by: Eddie Knight <iv.eddieknight@gmail.com>
Signed-off-by: Dhanraj Chavan <39642060+heydc7@users.noreply.github.com>
Signed-off-by: Dhanraj Chavan <39642060+heydc7@users.noreply.github.com>
@heydc7 heydc7 requested a review from eddie-knight December 12, 2023 05:27
Signed-off-by: Dhanraj Chavan <39642060+heydc7@users.noreply.github.com>
Signed-off-by: Dhanraj Chavan <39642060+heydc7@users.noreply.github.com>
@heydc7 heydc7 requested a review from eddie-knight December 12, 2023 18:29
ragashreeshekar and others added 2 commits January 16, 2024 14:14
Co-authored-by: torinvdb <65670557+torinvdb@users.noreply.github.com>
Signed-off-by: Raga <ragashreeshekar@gmail.com>
Co-authored-by: torinvdb <65670557+torinvdb@users.noreply.github.com>
Signed-off-by: Raga <ragashreeshekar@gmail.com>

### Security links

Provide the list of links to existing security documentation for the project. You may
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
Provide the list of links to existing security documentation for the project. You may


## Metadata

A table at the top for quick reference information, later used for indexing.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
A table at the top for quick reference information, later used for indexing.

Signed-off-by: Raga <ragashreeshekar@gmail.com>
@JustinCappos JustinCappos merged commit eb1bd33 into cncf:main Jan 25, 2024
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants