Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Review] WasmEdge #1337

Open
8 of 15 tasks
dm4 opened this issue Aug 1, 2024 · 29 comments
Open
8 of 15 tasks

[Security Review] WasmEdge #1337

dm4 opened this issue Aug 1, 2024 · 29 comments
Assignees
Labels
assessment project security assessments (one issue per project) triage-required Requires triage

Comments

@dm4
Copy link

dm4 commented Aug 1, 2024

The WasmEdge team would like to initiate the CNCF TAG-Security Security Assessment (TSSA) process.

Project Name: WasmEdge
Github URL: https://github.com/WasmEdge/WasmEdge
CNCF project stage and issue: cncf/toc#1316 (sandbox)
Security Provider: No

  • Identify team
  • Create slack channel #sec-assess-wasmedge
  • Project lead provides draft document (GDoc version, Markdown PR)
  • "Naive question phase" Lead Security Reviewer asks clarifying questions
  • Assign issue to security reviewers
  • Initial review
  • Presentation & discussion
  • Share draft findings with project
  • Assessment summary and doc checked into /community/assessments/projects/wasmedge (require at least 1 co-chair approval)
  • CNCF TOC presentation (if requested by TOC)
@JustinCappos
Copy link
Collaborator

We have three other assessments ongoing. We'll likely have the bandwidth for this in early September.

Who will be the project lead from your side?

@hydai
Copy link

hydai commented Aug 6, 2024

Hi @JustinCappos
I am a WasmEdge maintainer1, and I am going to be the project lead.
Since dm4 is OOO this week, I am submitting the self-assessment instead.

@hydai
Copy link

hydai commented Sep 20, 2024

Hi @JustinCappos

Is there anything else I should do before you start the review process, such as rebasing the PR?

@JustinCappos
Copy link
Collaborator

Where is the self assessment document at? You can update this issue to include a link.

@hydai
Copy link

hydai commented Sep 20, 2024

Where is the self assessment document at? You can update this issue to include a link.

Here is the PR: https://github.com/cncf/tag-security/pull/1343/files
Please feel free to let me know if you need more materials for the review process. Thanks.
Cc @dm4 Please check the draft document item.

@JustinCappos
Copy link
Collaborator

JustinCappos commented Sep 20, 2024 via email

@dm4
Copy link
Author

dm4 commented Sep 20, 2024

I just created a Google Doc to help us collaborate and edit files more easily. Thank you for your help.

https://docs.google.com/document/d/1Mv2AZRwkJjsjoputCyg_IuPk5gfFhQJuCx2fVigkic0/edit

@dm4
Copy link
Author

dm4 commented Oct 28, 2024

Just checking in to see if there are any updates on the security review for WasmEdge. Please let us know if there's anything else we can provide to help with the process. Thank you for your assistance and support.

@JustinCappos
Copy link
Collaborator

Okay, we need to recruit a group to do this assessment. We have an assessment ongoing currently, OSS Summit Japan is happening now and KubeCon NA is in 2 weeks. I think most likely this will not happen until after KubeCon NA. Sorry for the delay!

@victorjunlu
Copy link

I am interested as a participant.

@JustinCappos
Copy link
Collaborator

Great, @victorjunlu . Would you please read the guidelines and assert if you have a conflict?

@JustinCappos
Copy link
Collaborator

I'd also like to volunteer to be a security reviewer. I have no hard or soft conflicts.

@victorjunlu
Copy link

@JustinCappos Yes, I assert that I have no hard or soft conflicts. Thanks

@JustinCappos
Copy link
Collaborator

@brandtkeller @mnm678 @guilhermocc all expressed interest in being a reviewer. Can you each please read the guidelines and assert if you have any hard or soft conflicts?

@alabulei1
Copy link

Hi, @JustinCappos @victorjunlu @brandtkeller @mnm678 @guilhermocc Thank you all for your interest! It would be fantastic to have you as reviewers for WasmEdge. Feel free to let me know if you have any questions about WasmEdge.

@JustinCappos
Copy link
Collaborator

@brandtkeller @mnm678 @guilhermocc all expressed interest in being a reviewer. Can you each please read the guidelines and assert if you have any hard or soft conflicts?

@brandtkeller @mnm678 @guilhermocc Hope everyone made it back from KubeCon safely! When you get a chance, please read the guidelines and assert if you have a conflict?

@mnm678
Copy link
Collaborator

mnm678 commented Nov 21, 2024

I have no hard or soft conflicts.

@entlein
Copy link

entlein commented Nov 25, 2024

Hi @JustinCappos , I m happy to help in the review, too. I read the guidelines and have no conflicts whatsoever.

@mrcdb
Copy link
Member

mrcdb commented Nov 26, 2024

I am happy to lead this security review. I read the guidelines and I have neither hard or soft conflicts.

@JustinCappos
Copy link
Collaborator

Okay, thanks! @mrcdb we're ready to go with the naïve questions phase!

@mrcdb
Copy link
Member

mrcdb commented Nov 26, 2024

I just created a Google Doc to help us collaborate and edit files more easily. Thank you for your help.

https://docs.google.com/document/d/1Mv2AZRwkJjsjoputCyg_IuPk5gfFhQJuCx2fVigkic0/edit

@dm4 can you please copy the self-assessment content from the markdown (https://github.com/cncf/tag-security/pull/1343/files) to the Google Docs file? It's easier to work collectively on it and provide feedback/questions through the comment feature.

@mrcdb mrcdb added the assessment project security assessments (one issue per project) label Nov 26, 2024
@mrcdb mrcdb self-assigned this Nov 26, 2024
@hydai
Copy link

hydai commented Nov 26, 2024

Hi @mrcdb
I pasted the self-assessment content from the markdown to the docs. Please feel free to let me know if there are any issues, thanks.

@mrcdb
Copy link
Member

mrcdb commented Nov 26, 2024

Hi @mrcdb I pasted the self-assessment content from the markdown to the docs. Please feel free to let me know if there are any issues, thanks.

@dm4 I think the formatting looks broken as headings, tables and lists aren't looking right. Can you please ensure the formatting is consistent with the markdown preview?

@hydai
Copy link

hydai commented Nov 26, 2024

It should be fixed now. Please check again. Thanks.

@mrcdb
Copy link
Member

mrcdb commented Nov 26, 2024

Thanks @hydai ! A minor fix would be to remove the first section that mirrors the github issue description but other than that it looks good.

FYI I have requested edit access to the document, as the current permissions don't allow me to add comments.

@camilaavilarinho
Copy link

If possible I’d like to participate as an observer, since this would be my first security assessment here. I have no hard or soft conflicts.

@matthewflannery
Copy link
Collaborator

I'd like to participate as an observer, I have no conflicts.

@hydai
Copy link

hydai commented Nov 27, 2024

The first section is removed. I also updated the default permissions; it should be fine to add comments on the documents now. If you need, I can change the default permissions from commenter to editor. Thanks.

@JustinCappos
Copy link
Collaborator

@camilaavilarinho @matthewflannery Okay, added you both!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
assessment project security assessments (one issue per project) triage-required Requires triage
Projects
None yet
Development

No branches or pull requests

11 participants