-
Notifications
You must be signed in to change notification settings - Fork 521
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Volcano Project Security Self-Assessment - Security Pals #1205
Conversation
Signed-off-by: mayank-ramnani <[email protected]>
✅ Deploy Preview for tag-security canceled.
|
Co-authored-by: Eddie Knight <[email protected]> Signed-off-by: Mayank Ramnani <[email protected]>
…rent files Signed-off-by: mayank-ramnani <[email protected]>
Hi @eddie-knight @ragashreeshekar, |
|
||
## Self-assessment use | ||
|
||
This self-assessment is created by the Volcano team to perform an internal analysis of the project's security. It is not intended to provide a security audit of Volcano, or function as an independent assessment or attestation of Volcano's security health. |
This comment was marked as resolved.
This comment was marked as resolved.
Sorry, something went wrong.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
It was initially intended to be a collaboration between the Volcano team and the students, but we were unable to get any feedback from the team.
Fixed it to reflect the independence from the official team.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Ah okay, that makes more sense
@@ -0,0 +1,59 @@ | |||
# Lightweight Threat Modelling | |||
## Threat Modelling Notes | |||
- There are a total of 190 contributors and only 6 maintainers and owners thus there are 184 non-maintainer users who are in the working groups. |
This comment was marked as resolved.
This comment was marked as resolved.
Sorry, something went wrong.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I see. If it won't be helpful, it might be best to remove it.
Removed it from the notes and recommendations section.
@@ -0,0 +1,59 @@ | |||
# Lightweight Threat Modelling |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I'd be careful with the name as these notes are more akin to a lightweight threat analysis/enumeration as opposed to threat modeling which represents a comprehensive exercise (see: OWASP Threat Modeling Process).
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I agree, changed it to threat analysis instead.
Co-authored-by: torinvdb <[email protected]> Signed-off-by: Mayank R <[email protected]>
Co-authored-by: torinvdb <[email protected]> Signed-off-by: Mayank R <[email protected]>
Signed-off-by: mayank-ramnani <[email protected]>
Signed-off-by: Ragashree M C <[email protected]>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks good!
Created and added reviewed document for the Volcano Project Security Self-Assessment.
Please feel free to share any thoughts on the self-assessment.
@eddie-knight @ragashreeshekar @Rana-KV
Original PR: #1184 (discarded due to Git and DCO issues)