Skip to content

Commit

Permalink
parent cb0aac8
Browse files Browse the repository at this point in the history
author Andres Vega <[email protected]> 1700017197 -0800
committer Pratham Gupta <[email protected]> 1702406857 -0500

parent cb0aac8
author Andres Vega <[email protected]> 1700017197 -0800
committer Pratham Gupta <[email protected]> 1702406831 -0500

parent cb0aac8
author Andres Vega <[email protected]> 1700017197 -0800
committer Pratham Gupta <[email protected]> 1702406720 -0500

parent cb0aac8
author Andres Vega <[email protected]> 1700017197 -0800
committer Pratham Gupta <[email protected]> 1702406716 -0500

parent cb0aac8
author Andres Vega <[email protected]> 1700017197 -0800
committer Pratham Gupta <[email protected]> 1702406660 -0500

parent cb0aac8
author Andres Vega <[email protected]> 1700017197 -0800
committer Pratham Gupta <[email protected]> 1702406525 -0500

parent cb0aac8
author Andres Vega <[email protected]> 1700017197 -0800
committer Pratham Gupta <[email protected]> 1702406496 -0500

parent cb0aac8
author Andres Vega <[email protected]> 1700017197 -0800
committer Pratham Gupta <[email protected]> 1702406481 -0500

parent cb0aac8
author Andres Vega <[email protected]> 1700017197 -0800
committer Pratham Gupta <[email protected]> 1702406379 -0500

parent cb0aac8
author Andres Vega <[email protected]> 1700017197 -0800
committer Pratham Gupta <[email protected]> 1702406348 -0500

parent cb0aac8
author Andres Vega <[email protected]> 1700017197 -0800
committer Pratham Gupta <[email protected]> 1702406333 -0500

parent cb0aac8
author Andres Vega <[email protected]> 1700017197 -0800
committer Pratham Gupta <[email protected]> 1702406318 -0500

Update README.md with web page meet details

Copies the new words on TAG webpage on meeting times. This is for repo and page to be consistent.

This also consolidates meeting info, calendar, and zoom details in less words than what we had before.

Signed-off-by: Andres Vega <[email protected]>
Signed-off-by: Pratham Gupta <[email protected]>

Added Project Initial

Signed-off-by: Pratham Gupta <[email protected]>

Create self-assessment

Signed-off-by: BruceLiu10 <[email protected]>
Signed-off-by: Pratham Gupta <[email protected]>

Changes to self-assessment

Signed-off-by: Pratham Gupta <[email protected]>

Update self-assessment.md

Signed-off-by: BruceLiu10 <[email protected]>
Signed-off-by: Pratham Gupta <[email protected]>

Update self-assessment.md

Signed-off-by: BruceLiu10 <[email protected]>
Signed-off-by: Pratham Gupta <[email protected]>

Update self-assessment.md

Signed-off-by: BruceLiu10 <[email protected]>
Signed-off-by: Pratham Gupta <[email protected]>

Update self-assessment.md

Signed-off-by: BruceLiu10 <[email protected]>
Signed-off-by: Pratham Gupta <[email protected]>

Update self-assessment.md

Signed-off-by: BruceLiu10 <[email protected]>
Signed-off-by: Pratham Gupta <[email protected]>

Update self-assessment.md

Signed-off-by: BruceLiu10 <[email protected]>
Signed-off-by: Pratham Gupta <[email protected]>

Update self-assessment.md

Signed-off-by: BruceLiu10 <[email protected]>
Signed-off-by: Pratham Gupta <[email protected]>

Update self-assessment.md

Signed-off-by: BruceLiu10 <[email protected]>
Signed-off-by: Pratham Gupta <[email protected]>

Added table of content

Signed-off-by: Pratham Gupta <[email protected]>

Changes to table of contents

Signed-off-by: Pratham Gupta <[email protected]>

Open and Secure Assessments Book

Adds final proofed version of the book

Signed-off-by: Andres Vega <[email protected]>
Signed-off-by: Pratham Gupta <[email protected]>

Delete assessments/Open_and_Secure_Early_Access.pdf

Signed-off-by: Andres Vega <[email protected]>
Signed-off-by: Pratham Gupta <[email protected]>

Fix repeated words in acknowledgements

Signed-off-by: Andres Vega <[email protected]>
Signed-off-by: Pratham Gupta <[email protected]>

Update README.md

Small but important update. My name is currently listed with an affiliation to the previous company name. As I am no longer associated with this organization, I'm removing the reference to this prior employer while retaining my name on the list.

Signed-off-by: Andres Vega <[email protected]>
Signed-off-by: Pratham Gupta <[email protected]>

Replace pdf to fix link to security lexicon

Replace pdf to fix link to security lexicon

Signed-off-by: Andres Vega <[email protected]>
Signed-off-by: Pratham Gupta <[email protected]>

Fixes hyperlinks and styling,

- Two hyperlinks p25
- Expand text on p45
- Italicize 60-61

Signed-off-by: Andres Vega <[email protected]>
Signed-off-by: Pratham Gupta <[email protected]>

Update _index.md

Signed-off-by: Pratham Gupta <[email protected]>

OAS - Adds commentary and double strokes lines

Adds Ann Wallace's commentary and double stroke to other comments

Signed-off-by: Andres Vega <[email protected]>
Signed-off-by: Pratham Gupta <[email protected]>

Max 11 24 (#3)

* Max's edits
Added Actors and Background
Cleaned up some files

* Cleanup

Update self-assessment.md

Grammar fixes

Signed-off-by: bbtc33 <[email protected]>
Signed-off-by: Pratham Gupta <[email protected]>

Update self-assessment.md

Signed-off-by: Inkhermit <[email protected]>
Signed-off-by: Pratham Gupta <[email protected]>

Update self-assessment.md

Signed-off-by: Inkhermit <[email protected]>
Signed-off-by: Pratham Gupta <[email protected]>

Update self-assessment.md

Signed-off-by: BruceLiu10 <[email protected]>

Added Secure Developmental Practices

Signed-off-by: Pratham Gupta <[email protected]>

Changes to Secure Developmental Practices

Signed-off-by: Pratham Gupta <[email protected]>

Added Security Issue Resolution

Signed-off-by: Pratham Gupta <[email protected]>

Deleted some files

Signed-off-by: Pratham Gupta <[email protected]>

Updated BOM for OpenTelemetry

Signed-off-by: Pratham Gupta <[email protected]>

Edited title

Signed-off-by: Pratham Gupta <[email protected]>

Added Comment for Finishing First Draft

Update self-assessment.md

Update the Non-Goals and Self-Assessment Use

Signed-off-by: BruceLiu10 <[email protected]>
Signed-off-by: Pratham Gupta <[email protected]>

Update self-assessment.md

Update the Appendix's Known Issues Over Time and Related Projects/Vendors parts.

Signed-off-by: BruceLiu10 <[email protected]>
Signed-off-by: Pratham Gupta <[email protected]>

Max's edits
Added Actors and Background
Cleaned up some files

Signed-off-by: Pratham Gupta <[email protected]>

Max Yin
Updated Security links, Background/Overview and Actors.
Also deleted the pixie template as it is not needed anymore

Signed-off-by: Pratham Gupta <[email protected]>

Update self-assessment.md

Signed-off-by: Inkhermit <[email protected]>
Signed-off-by: Pratham Gupta <[email protected]>

Update self-assessment.md

Signed-off-by: Inkhermit <[email protected]>
Signed-off-by: Pratham Gupta <[email protected]>

Update self-assessment.md

Signed-off-by: Inkhermit <[email protected]>
Signed-off-by: Pratham Gupta <[email protected]>

Update self-assessment.md

Signed-off-by: Inkhermit <[email protected]>
Signed-off-by: Pratham Gupta <[email protected]>

Add OAS to PUBLICATIONS.md

Signed-off-by: Andres Vega <[email protected]>
Signed-off-by: Pratham Gupta <[email protected]>

Update README.md

Removes policy wg from ongoing efforts as the effort is no longer active within TAG Security as it has moved outside the group.

Signed-off-by: Andres Vega <[email protected]>
Signed-off-by: Pratham Gupta <[email protected]>

Add feedback buttons to pages

Signed-off-by: Chris Abraham <[email protected]>
Signed-off-by: Pratham Gupta <[email protected]>

Bump postcss and autoprefixer in /website/themes/docsy/userguide (cncf#1118)

Bumps [postcss](https://github.com/postcss/postcss) to 8.4.31 and updates ancestor dependency [autoprefixer](https://github.com/postcss/autoprefixer). These dependencies need to be updated together.

Updates `postcss` from 7.0.39 to 8.4.31
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@7.0.39...8.4.31)

Updates `autoprefixer` from 9.5.0 to 10.4.16
- [Release notes](https://github.com/postcss/autoprefixer/releases)
- [Changelog](https://github.com/postcss/autoprefixer/blob/main/CHANGELOG.md)
- [Commits](postcss/autoprefixer@9.5.0...10.4.16)

---
updated-dependencies:
- dependency-name: postcss
  dependency-type: indirect
- dependency-name: autoprefixer
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: Pratham Gupta <[email protected]>

Bump postcss from 8.4.20 to 8.4.31 in /website (cncf#1120)

Signed-off-by: Pratham Gupta <[email protected]>

Update self-assessment.md

Changing the details on Related Projects/Vendors

Signed-off-by: BruceLiu10 <[email protected]>
Signed-off-by: Pratham Gupta <[email protected]>

Update self-assessment.md

Changing the Goals and Non-Goals

Signed-off-by: BruceLiu10 <[email protected]>
Signed-off-by: Pratham Gupta <[email protected]>

Changes to Security Development and Security Issue Resolution

Signed-off-by: Pratham Gupta <[email protected]>

Deleted the templates

Signed-off-by: Pratham Gupta <[email protected]>

Add translator IDs

Signed-off-by: Jimmy Song <[email protected]>

Update security-whitepaper/v2/cloud-native-security-whitepaper-simplified-chinese.md

Co-authored-by: Michael <[email protected]>
Signed-off-by: Jimmy Song <[email protected]>

Update security-whitepaper/v2/cloud-native-security-whitepaper-simplified-chinese.md

Co-authored-by: Michelle Wu <[email protected]>
Signed-off-by: Jimmy Song <[email protected]>

Update security-whitepaper/v2/cloud-native-security-whitepaper-simplified-chinese.md

Co-authored-by: Mengjiao Liu <[email protected]>
Signed-off-by: Jimmy Song <[email protected]>

Update security-whitepaper/v2/cloud-native-security-whitepaper-simplified-chinese.md

Co-authored-by: Mengjiao Liu <[email protected]>
Signed-off-by: Jimmy Song <[email protected]>

Update README.md

Removes anvega's prior employer as he no longer represents that company.

Signed-off-by: Andres Vega <[email protected]>

Update security-whitepaper/v2/cloud-native-security-whitepaper-simplified-chinese.md

Co-authored-by: Mengjiao Liu <[email protected]>
Signed-off-by: Jimmy Song <[email protected]>

remove blank space

Signed-off-by: Jimmy Song <[email protected]>

add acronym

Signed-off-by: Jimmy Song <[email protected]>

Update security-whitepaper/v2/cloud-native-security-whitepaper-simplified-chinese.md

Co-authored-by: Michael <[email protected]>
Signed-off-by: Jimmy Song <[email protected]>

Add cloud native security whitepaper in Japanese

Signed-off-by: Nao Nishijima <[email protected]>

add assessment documents

Signed-off-by: Michelle Nguyen <[email protected]>

Add the Chinese issue of Cloud Native Whitepaper v2

Signed-off-by: Jimmy Song <[email protected]>

Update README.md

Enlarges logo to full width

Signed-off-by: Andres Vega <[email protected]>

Added express learning course link to self-assessments.md

Signed-off-by: Eddie Knight <[email protected]>

Added provenance-implementation hub w/ README and example

Signed-off-by: Eddie Knight <[email protected]>

Add fuzzing handbook

Signed-off-by: David Korczynski <[email protected]>

Updating Twitter logo to X

Signed-off-by: James Hunt <[email protected]>

Chair transition Aradhna -> Marina (cncf#1126)

Update unconference.md

Update unconference issue template in order to make it clearer that this is about cloud native security.

Signed-off-by: Michael Lieberman <[email protected]>

Update _index.md

Improve phrasing.

Signed-off-by: Andres Vega <[email protected]>

Add Assessments Book Early Access Copy

Signed-off-by: Andres Vega <[email protected]>

Update README.md with web page meet details

Copies the new words on TAG webpage on meeting times. This is for repo and page to be consistent.

This also consolidates meeting info, calendar, and zoom details in less words than what we had before.

Signed-off-by: Andres Vega <[email protected]>

Added Project Initial

Create self-assessment

Signed-off-by: BruceLiu10 <[email protected]>

Update self-assessment.md

Signed-off-by: BruceLiu10 <[email protected]>

Added table of content

Changes to table of contents

Delete assessments/Open_and_Secure_Early_Access.pdf

Signed-off-by: Andres Vega <[email protected]>

Update README.md

Small but important update. My name is currently listed with an affiliation to the previous company name. As I am no longer associated with this organization, I'm removing the reference to this prior employer while retaining my name on the list.

Signed-off-by: Andres Vega <[email protected]>

Update _index.md

OAS - Adds commentary and double strokes lines

Adds Ann Wallace's commentary and double stroke to other comments

Signed-off-by: Andres Vega <[email protected]>

Max 11 24 (#3)

* Max's edits
Added Actors and Background
Cleaned up some files

* Cleanup

Update self-assessment.md

Signed-off-by: BruceLiu10 <[email protected]>

Deleted some files

Updated BOM for OpenTelemetry

Update self-assessment.md

Update the Appendix's Known Issues Over Time and Related Projects/Vendors parts.

Signed-off-by: BruceLiu10 <[email protected]>

Max's edits
Added Actors and Background
Cleaned up some files

Max Yin
Updated Security links, Background/Overview and Actors.
Also deleted the pixie template as it is not needed anymore

Update self-assessment.md

Signed-off-by: Inkhermit <[email protected]>

Update self-assessment.md

Signed-off-by: Inkhermit <[email protected]>

Update self-assessment.md

Signed-off-by: Inkhermit <[email protected]>

Update self-assessment.md

Signed-off-by: Inkhermit <[email protected]>

Add OAS to PUBLICATIONS.md

Signed-off-by: Andres Vega <[email protected]>

Update README.md

Removes policy wg from ongoing efforts as the effort is no longer active within TAG Security as it has moved outside the group.

Signed-off-by: Andres Vega <[email protected]>

Add feedback buttons to pages

Signed-off-by: Chris Abraham <[email protected]>

Bump postcss and autoprefixer in /website/themes/docsy/userguide (cncf#1118)

Bumps [postcss](https://github.com/postcss/postcss) to 8.4.31 and updates ancestor dependency [autoprefixer](https://github.com/postcss/autoprefixer). These dependencies need to be updated together.

Updates `postcss` from 7.0.39 to 8.4.31
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@7.0.39...8.4.31)

Updates `autoprefixer` from 9.5.0 to 10.4.16
- [Release notes](https://github.com/postcss/autoprefixer/releases)
- [Changelog](https://github.com/postcss/autoprefixer/blob/main/CHANGELOG.md)
- [Commits](postcss/autoprefixer@9.5.0...10.4.16)

---
updated-dependencies:
- dependency-name: postcss
  dependency-type: indirect
- dependency-name: autoprefixer
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

Bump postcss from 8.4.20 to 8.4.31 in /website (cncf#1120)

Update self-assessment.md

Changing the details on Related Projects/Vendors

Signed-off-by: BruceLiu10 <[email protected]>

Update self-assessment.md

Changing the Goals and Non-Goals

Signed-off-by: BruceLiu10 <[email protected]>

Changes to Security Development and Security Issue Resolution

Deleted the templates

Implement contributor's suggestions

cleaned up non-goals
simplified some of the goals, still needs work

Signed-off-by: Max <[email protected]>

Update self-assessment.md

Update the Case Studies

Signed-off-by: BruceLiu10 <[email protected]>

Changes in actors

Signed-off-by: Pratham Gupta <[email protected]>

Made changes to OpenTelemetry Collector

Signed-off-by: Pratham Gupta <[email protected]>
  • Loading branch information
anvega authored and PrathamGupta committed Dec 12, 2023
1 parent cb0aac8 commit 7e35bd6
Show file tree
Hide file tree
Showing 13 changed files with 483 additions and 205 deletions.
86 changes: 49 additions & 37 deletions PUBLICATIONS.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,20 @@
This document lists all the publications and resources that TAG Security has
produced.

## Cloud Native Security Controls Catalog

Mapping of Cloud Native Security Whitepaper and Software Supply Chain Best
Practices Paper to NIST SP800-53r5

- [Markdown](https://github.com/cncf/tag-security/blob/main/cloud-native-controls/phase-one-announcement.md)
- [Spreadsheet](https://docs.google.com/spreadsheets/d/1GUohOTlLw9FKUQ3O23X7ypvJLXN-B3veJGe6YE6JYfU/edit?usp=sharing)

## Cloud Native Security Lexicon

Standardization of terminologies specific to Cloud Native Security

- [Markdown](https://github.com/cncf/tag-security/blob/main/security-lexicon/cloud-native-security-lexicon.md)

## Cloud Native Security Whitepaper

The Cloud Native Security Whitepaper (CNSWP) is a TAG Security effort to ensure
Expand All @@ -23,6 +37,41 @@ Translations
- [Chinese](https://github.com/cncf/tag-security/blob/main/security-whitepaper/v1/cloud-native-security-whitepaper-simplified-chinese.md)
(v1)

## Open and Secure - A Manual for Practicing Threat Modeling to Assess and Fortify Open Source Security

A comprehensive guide dedicated to assessing and understanding the security of open source software projects. The book is the culmination of five years of TAG Secure Assessments, practical insights, and collaborative effort from experts in the field. Our goal? To empower you with the knowledge and skills to enhance the security of the cloud native ecosystem, the projects, and their use in your organization’s platforms.

- [PDF](https://github.com/cncf/tag-security/blob/main/assessments/Open_and_Secure.pdf)

## Policy

### Formal Verification for Policy Configurations

- [Markdown](https://github.com/cncf/tag-security/blob/main/policy/overview-policy-formal-verification.md)

### Handling build-time dependency vulnerabilities

- [Markdown](https://github.com/cncf/tag-security/blob/main/policy/overview-policy-build-time-dependency-vulns.md)

## Secure Defaults: Cloud Native 8

- [Markdown](https://github.com/cncf/tag-security/blob/main/security-whitepaper/secure-defaults-cloud-native-8.md)

## Security Assessments

TAG Security has conducted security assessments of several CNCF projects. These
assessments are available to the public.

- [Buildpacks](https://github.com/cncf/tag-security/tree/main/assessments/projects/buildpacks)
- [Cloud
Custodian](https://github.com/cncf/tag-security/tree/main/assessments/projects/custodian)
- [Harbor](https://github.com/cncf/tag-security/tree/main/assessments/projects/harbor)
- [In-toto](https://github.com/cncf/tag-security/tree/main/assessments/projects/in-toto)
- [Keycloak](https://github.com/cncf/tag-security/tree/main/assessments/projects/keycloak)
- [Kyverno](https://github.com/cncf/tag-security/tree/main/assessments/projects/kyverno)
- [OPA](https://github.com/cncf/tag-security/tree/main/assessments/projects/opa)
- [Spiffe-Spire](https://github.com/cncf/tag-security/tree/main/assessments/projects/spiffe-spire)

## Supply Chain Security

### Software Supply Chain Best Practices
Expand Down Expand Up @@ -54,11 +103,7 @@ them

- [Markdown](https://github.com/cncf/tag-security/tree/main/supply-chain-security/compromises)

## Cloud Native Security Lexicon

Standardization of terminologies specific to Cloud Native Security

- [Markdown](https://github.com/cncf/tag-security/blob/main/security-lexicon/cloud-native-security-lexicon.md)

## Use Cases & Personas

Expand All @@ -67,39 +112,6 @@ of cloud native technology

- [Markdown](https://github.com/cncf/tag-security/blob/main/usecase-personas/README.md)

## Policy

### Formal Verification for Policy Configurations

- [Markdown](https://github.com/cncf/tag-security/blob/main/policy/overview-policy-formal-verification.md)

### Handling build-time dependency vulnerabilities

- [Markdown](https://github.com/cncf/tag-security/blob/main/policy/overview-policy-build-time-dependency-vulns.md)

## Secure Defaults: Cloud Native 8

- [Markdown](https://github.com/cncf/tag-security/blob/main/security-whitepaper/secure-defaults-cloud-native-8.md)

## Cloud Native Security Controls Catalog

Mapping of Cloud Native Security Whitepaper and Software Supply Chain Best
Practices Paper to NIST SP800-53r5

- [Markdown](https://github.com/cncf/tag-security/blob/main/cloud-native-controls/phase-one-announcement.md)
- [Spreadsheet](https://docs.google.com/spreadsheets/d/1GUohOTlLw9FKUQ3O23X7ypvJLXN-B3veJGe6YE6JYfU/edit?usp=sharing)

## Security Assessments

TAG Security has conducted security assessments of several CNCF projects. These
assessments are available to the public.

- [Buildpacks](https://github.com/cncf/tag-security/tree/main/assessments/projects/buildpacks)
- [Cloud
Custodian](https://github.com/cncf/tag-security/tree/main/assessments/projects/custodian)
- [Harbor](https://github.com/cncf/tag-security/tree/main/assessments/projects/harbor)
- [In-toto](https://github.com/cncf/tag-security/tree/main/assessments/projects/in-toto)
- [Keycloak](https://github.com/cncf/tag-security/tree/main/assessments/projects/keycloak)
- [Kyverno](https://github.com/cncf/tag-security/tree/main/assessments/projects/kyverno)
- [OPA](https://github.com/cncf/tag-security/tree/main/assessments/projects/opa)
- [Spiffe-Spire](https://github.com/cncf/tag-security/tree/main/assessments/projects/spiffe-spire)
48 changes: 7 additions & 41 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -74,38 +74,17 @@ and posting to the channels.

## Meeting times

Group meeting times are listed below:
For our members in North and South America, we host weekly sessions each Wednesday at 10 am (UTC-7). To participate, simply use the following Zoom link: https://zoom.us/j/99809474566. The meeting ID is 998 0947 4566.

- US: Weekly on Wednesdays at 10 am UTC-7 (see your timezone
[here](https://time.is/1000_today_in_PT?CNCF_Security_TAG_US_Meeting))
- EMEA: Bi-weekly on Wednesdays at 1 pm UTC+0 (UTC+1 while observing daylight savings) (see your timezone
[here](https://time.is/UTC?CNCF_Security_TAG_EMEA_Meeting))
Meanwhile, participants from Europe, the Middle East, and Africa (EMEA) can join bi-weekly meetings on Wednesdays at 1 pm UTC+0, which adjusts to UTC+1 when daylight saving time is in effect. Join us through this Zoom link: https://zoom.us/j/99917523142, with the meeting ID: 999 1752 3142.

[Meeting minutes and agenda](https://docs.google.com/document/d/170y5biX9k95hYRwprITprG6Mc9xD5glVn-4mB2Jmi2g/)
To find the corresponding time in your local area, please see your timezone [here]([url](https://time.is/)).

### Calendar
This dual schedule ensures that no matter where you are, you'll have a place in our conversations.

- Here is a [TAG-Security curated calendar](https://calendar.google.com/calendar/u/0?cid=MGI4dTVlbDh0YTRzOTN0MmNtNzJ0dXZoaGtAZ3JvdXAuY2FsZW5kYXIuZ29vZ2xlLmNvbQ)
with the main meetings and working groups.
- See the [CNCF Calendar](https://www.cncf.io/calendar/) for a list of all CNCF calendar
invites.
We invite you to mark your calendars and join the dialogue. For your convenience, all meetings are listed on the main [CNCF calendar](https://www.cncf.io/calendar/) as well as the [TAG Security Calendar](https://calendar.google.com/calendar/u/0?cid=MGI4dTVlbDh0YTRzOTN0MmNtNzJ0dXZoaGtAZ3JvdXAuY2FsZW5kYXIuZ29vZ2xlLmNvbQ). These calendars are updated regularly to ensure that you stay informed of all upcoming meetings and events.

Got something to bring up or share? Review how to get a topic or presentation
added to the Agenda on our [process](governance/process.md#getting-on-the-agenda) page.

### Zoom Meeting Details

#### [North America] CNCF TAG-Security Weekly Meeting

https://zoom.us/j/99809474566

Meeting ID: 998 0947 4566

#### [EMEA] CNCF TAG-Security Weekly Meeting

https://zoom.us/j/99917523142

Meeting ID: 999 1752 3142
Got something to bring up or share? Review how to get a topic or presentation added to the Agenda on our [process](governance/process.md#getting-on-the-agenda) page.

## Gatherings

Expand Down Expand Up @@ -172,19 +151,6 @@ seen [here](governance/related-groups/)

### On-going projects

#### Policy team

Policy is an essential component of a secure system.

[Bi-weekly meetings](https://docs.google.com/document/d/1ihFfEfgViKlUMbY2NKxaJzBkgHh-Phk5hqKTzK-NEEs/edit?usp=sharing)
at 3:00 PM PT focus on policy concerns and initiatives.

Co-leads

- TBD

Co-chair representative: @achetal01

#### Security reviews

[Security reviews](./assessments) are a collaborative process for the benefit of
Expand All @@ -194,7 +160,7 @@ the project and its risk profile.
Facilitator: Justin Cappos ([@JustinCappos](https://github.com/JustinCappos)),
New York University

Facilitator: Andres Vega ([@anvega](https://github.com/anvega)), ControlPlane
Facilitator: Andrés Vega ([@anvega](https://github.com/anvega))

Co-chair representatives: @sublimino @PushkarJ

Expand Down
Binary file added assessments/Open_and_Secure.pdf
Binary file not shown.
Binary file removed assessments/Open_and_Secure_Early_Access.pdf
Binary file not shown.
Loading

0 comments on commit 7e35bd6

Please sign in to comment.