tag-security icon indicating copy to clipboard operation
tag-security copied to clipboard

[Security Review] Keptn

Open thisthat opened this issue 4 years ago • 17 comments
trafficstars

Project Name: Keptn

Github URL: https://github.com/keptn/keptn

CNCF project stage and issue: https://github.com/cncf/toc/pull/670 (incubation)

Security Provider: no

  • [ ] Identify team
    • [ ] Project security lead: @thisthat
    • [ ] Lead security reviewer
    • [ ] 1 or more additional reviewer(s)
    • [ ] Every reviewer has read security reviewer guidelines and stated declaration of conflict
    • [ ] Sign off by 2 chairs on reviewer conflicts
  • [ ] Create slack channel (e.g. #sec-assess-projectname)
  • [ ] Project lead provides draft document - see outline
  • [ ] "Naive question phase" Lead Security Reviewer asks clarifying questions
  • [ ] Assign issue to security reviewers
  • [ ] Initial review
  • [ ] Presentation & discussion
  • [ ] Share draft findings with project
  • [ ] Assessment summary and doc checked into /assessments/projects/project-name (require at least 1 co-chair approval)
  • [ ] CNCF TOC presentation (if requested by TOC)

thisthat avatar Sep 07 '21 13:09 thisthat

@IAXES CC: @ashutosh-narkar

TheFoxAtWork avatar Sep 08 '21 17:09 TheFoxAtWork

ping @IAXES CC: @ashutosh-narkar

lumjjb avatar Sep 29 '21 18:09 lumjjb

Is there any ETA when the review will be done for Keptn? (cc @thisthat)

jetzlstorfer avatar Oct 05 '21 07:10 jetzlstorfer

👋🏻 Our current pipeline shows a wrap up of Cloud Custodian (very nearly complete) then we begin Argo, Keptn would be next. CC: @IAXES @lumjjb @ashutosh-narkar

Provided we can have volunteers for Argo and get it started soon, i would anticipate this (Keptn) beginning in Dec/Jan

TheFoxAtWork avatar Oct 05 '21 13:10 TheFoxAtWork

👋🏻 Our current pipeline shows a wrap up of Cloud Custodian (very nearly complete) then we begin Argo, Keptn would be next. CC: @IAXES @lumjjb @ashutosh-narkar

Provided we can have volunteers for Argo and get it started soon, i would anticipate this (Keptn) beginning in Dec/Jan

Sounds about right to me. Looks like we'll have volunteers ready for Argo (it's just being pushed back a few weeks due to Kubecon).

IAXES avatar Oct 05 '21 23:10 IAXES

thanks for the updates. Can we plan to have our security review in Dec/Jan? Are there any more resources needed from our end to start the process? CC: @thisthat @oleg-nenashev

jetzlstorfer avatar Nov 04 '21 08:11 jetzlstorfer

This issue has been automatically marked as inactive because it has not had recent activity.

stale[bot] avatar Jan 03 '22 19:01 stale[bot]

Is there any update on this? cc @thisthat @oleg-nenashev

jetzlstorfer avatar Jan 04 '22 16:01 jetzlstorfer

Good day,

We're currently going through the Argo assessment, and then will be re-visiting this review.

IAXES avatar Jan 04 '22 16:01 IAXES

Hi all. Please let us know if any additional info is needed from our side. IIUC the review ETA in Feb 2022 needs top be pushed for later months, right @IAXES @TheFoxAtWork ?

oleg-nenashev avatar Feb 17 '22 16:02 oleg-nenashev

This issue has been automatically marked as inactive because it has not had recent activity.

stale[bot] avatar Apr 18 '22 20:04 stale[bot]

Not stale but stuck

oleg-nenashev avatar Apr 21 '22 15:04 oleg-nenashev

FTR ongoing discussion with @TheFoxAtWork and @lumjjb : https://cloud-native.slack.com/archives/CDJ7MLT8S/p1650549287843639

oleg-nenashev avatar Apr 21 '22 15:04 oleg-nenashev

we had a chat yesterday, the current plan is to get the self-assessment PR in, we will review it and give a DD recommendation based on that if no red flags.

lumjjb avatar Apr 22 '22 12:04 lumjjb

This issue has been automatically marked as inactive because it has not had recent activity.

stale[bot] avatar Jun 23 '22 00:06 stale[bot]

Hi! Quick update on Keptn security review. The previous self-assessment doc needs some updates based on the roadmap changes we had in the project (Keptn 1.0 discussions, etc.). I plan top provide the new version by Wednesday. I have not touched this topic since May due to other discussions, my apologies for that. At least we can now schedule the security review for the real scope.

oleg-nenashev avatar Aug 15 '22 15:08 oleg-nenashev

@IAXES fyi - just assigned the issue

lumjjb avatar Aug 15 '22 16:08 lumjjb

This issue has been automatically marked as inactive because it has not had recent activity.

stale[bot] avatar Oct 16 '22 08:10 stale[bot]

I'm picking up stale items in the security assessment queue to try to push them forward. Apologies for the delay on your assessment!

Is an updated self-assessment available? I don't see it in the repo, etc. Once this happens, we can get a team together to do an assessment. Once it reaches the front of our queue, this will require back and forth with your team.

If a security assessment isn't desired anymore, please let us know and this issue can be closed.

JustinCappos avatar Jul 07 '23 13:07 JustinCappos

Found in the slack thread there is a google docs version of the assessment although the last update is 5 days before the comment above stating the document needs updating.

https://docs.google.com/document/d/14qFAc6kxhWX_JLMUKddgELcymaRw6jmhsq0OYxrHtc0/edit#bookmark=id.19yjmziudbxj

anvega avatar Jul 09 '23 01:07 anvega

Thanks for picking up this item :) As a Keptn Community, we decided to move the project's effort to a new repo, the lifecycle toolkit. You can see the decision here: https://github.com/keptn/enhancement-proposals/pull/100 I've updated the original message pointing to the new repo. The document definitely needs to be updated to reflect the latest changes.

thisthat avatar Jul 11 '23 12:07 thisthat

Okay, sounds good! Please ping us once you have your self assessment ready.

JustinCappos avatar Jul 11 '23 15:07 JustinCappos

This issue has been automatically marked as inactive because it has not had recent activity.

stale[bot] avatar Sep 17 '23 01:09 stale[bot]

Let us know if you decide to move ahead with this again. I'll close this issue for now, but feel free to reopen it / open a fresh one when you have the time to do the self assessment.

JustinCappos avatar Sep 17 '23 04:09 JustinCappos