tag-security
tag-security copied to clipboard
Website Content Review
trafficstars
Link to website: https://tag-security.cncf.io/
In order to increase the quality of outputs from TAG Security, to simplify the project maintenance, and to streamline new member familiarization, there is a need to do a large-scale cleanup of this repository. This will involve the revision or removal of files and/or directories.
As a first phase, we will be scoping focus specifically to content that is displayed on the website:
# snippet from website/Makefile
--include='assessments' --include='assessments/**' \
--include='governance' --include='governance/**' \
--include='supply-chain-security' --include='supply-chain-security/**' \
--include='*.md' --exclude='*'
This issue description will be used to summarize unique work items that we have found, which should be tackled. Unless otherwise noted, PRs and comments are welcome from anyone in the community to address the questions or problems outlined below.
Action Items
### Assessments
- [x] README: Minor typos
- [x] README: Simplify language / reduce length
- [x] README: Does "Components of the TSSA package" imply that a STAG review required by the TOC must involve a self- and joint- assessment? (It shouldn't reference the TOC at all)
- [x] guide/self-assessment: Ensure all language surrounding intent or usage matches the current strategy for reviews and assessments
### Events
- [x] README: Add new heading for "Recurring Events"
- [x] Move events into primary repo structure (outside of website/content/)
### Governance
- [x] Consistent capitalization of page titles (this applies to every section, really)
- [ ] roles: Should we consolidate all of the different roles files into the core roles.md?
- [x] charter: TODO: Review this with current TAG leadership. (Is the Charter up to date? Have we been properly acting in accordance with the charter goals and commitments? Are we using it to effectively equip and onboard leaders?)
- [ ] comunications: Is this used? Should it be used more? (no, no) (#1301)
- [x] presentations: Is this up to date? (yes)
- [ ] process: Is this up to date? (yes, but it's duplicative with CONTRIBUTORS.md)
- [x] related-groups: This seems incomplete (#1261)
- [ ] tools: This seems like a stub, and it seems like it might not be governance related (#1301)
- [x] Full Directory: Move anything that pertains to contribution governance (members, groups, etc) to a new directory. Remove Governance from the website.
- [ ] CNCF-projects: replace this with a [link to the landscape](https://landscape.cncf.io/?group=projects-and-products&view-mode=grid&tag=security) (#1300)
### Supply Chain Security
- [x] **/images: we should create a naming convention for image directories, and omit them all from showing up in the sidebar
- [x] Is the secure software factory a whitepaper? Should we have a top-level directory for whitepapers instead, and include all of them there? TODO: Co-chairs meet to decide approach.
### Blog
- [x] Do we want to keep the blog? (yes)
- [x] Do we want to keep the old blogs?
- [x] Do we want to add new blogs?
- [ ] TODO: document the intent, standards, and process for contributing (governance or contributing dir?)
- [x] TODO: add structure for organizing by year
### Publications
- [ ] The publications table is too wide— in the final column "Link" four letters is getting broken up into two lines.