Skip to content

Address CNCF TAG Security and Compliance feedback on self-assessment#2034

Merged
ytsarev merged 1 commit intok8gb-io:masterfrom
ytsarev:sec-self-assessment-feedback
Aug 24, 2025
Merged

Address CNCF TAG Security and Compliance feedback on self-assessment#2034
ytsarev merged 1 commit intok8gb-io:masterfrom
ytsarev:sec-self-assessment-feedback

Conversation

@ytsarev
Copy link
Copy Markdown
Member

@ytsarev ytsarev commented Aug 23, 2025

Updates the k8gb security self-assessment document based on feedback from cncf/tag-security#1446.

Changes:

  • Define acronyms on first use throughout document
  • Update references to "CNCF TAG Security and Compliance"
  • Enhance overview section with clearer context and explanations
  • Replace placeholder "Future state" section with actual compliance content
  • Clarify risk reduction comparisons with specific context
  • Correctly reflect SLSA Level 3 compliance with signed provenance
  • Distinguish between functional and security-focused pipeline components

These improvements make the self-assessment more accessible to readers unfamiliar with k8gb while accurately representing the project's security practices and compliance achievements.

..

HOW TO RUN CI ---

By default, all the checks will be run automatically. Furthermore, when changing website-related stuff, the preview will be generated by the netlify bot.

Heavy tests

Add the heavy-tests label on this PR if you want full-blown tests that include more than 2-cluster scenarios.

Debug tests

If the test suite is failing for you, you may want to try triggering Re-run all jobs (top right) with debug logging enabled. It will also make the print debug action more verbose.

Updates the k8gb security self-assessment document based on feedback from
cncf/tag-security#1446.

Changes:

- Define acronyms on first use throughout document
- Update references to "CNCF TAG Security and Compliance"
- Enhance overview section with clearer context and explanations
- Replace placeholder "Future state" section with actual compliance content
- Clarify risk reduction comparisons with specific context
- Correctly reflect SLSA Level 3 compliance with signed provenance
- Distinguish between functional and security-focused pipeline components

These improvements make the self-assessment more accessible to readers unfamiliar with k8gb while accurately
representing the project's security practices and compliance achievements.

Signed-off-by: Yury Tsarev <yury@upbound.io>
@ytsarev ytsarev merged commit 7cb782c into k8gb-io:master Aug 24, 2025
1 check passed
@ytsarev ytsarev deleted the sec-self-assessment-feedback branch August 24, 2025 09:04
itsfarhan pushed a commit to itsfarhan/k8gb that referenced this pull request Sep 3, 2025
…8gb-io#2034)

Updates the k8gb security self-assessment document based on feedback from
cncf/tag-security#1446.

Changes:

- Define acronyms on first use throughout document
- Update references to "CNCF TAG Security and Compliance"
- Enhance overview section with clearer context and explanations
- Replace placeholder "Future state" section with actual compliance content
- Clarify risk reduction comparisons with specific context
- Correctly reflect SLSA Level 3 compliance with signed provenance
- Distinguish between functional and security-focused pipeline components

These improvements make the self-assessment more accessible to readers unfamiliar with k8gb while accurately
representing the project's security practices and compliance achievements.

Signed-off-by: Yury Tsarev <yury@upbound.io>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants