Skip to content

[CNCF Graduation][Security][Required] Publish third-party security audit evidence for DD validation #992

Description

@kfaseela

For Graduation DD(cncf/toc#1861), the Third Party Security Review criterion is required and currently needs reviewer-verifiable evidence.

Could you please publish and link:

  1. A public third-party audit report (or a public summary if full report cannot be shared), and
  2. Evidence that findings are tracked/resolved (public issues/changelog/release notes, or reviewer-visible artifact shared with TOC/TAG Security).

Please add the link(s) in the graduation issue Security section as well as into your appropriate project security docs/website, so DD reviewers can validate quickly.

Reference examples:

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions