cncf / tag-security

🔐CNCF Security Technical Advisory Group -- secure access, policy control, privacy, auditing, explainability and more!
https://cncf.io/projects
Other
1.99k stars 496 forks source link

Emissary- Ingress Security self assessment and Thread Model #1187

Closed Disha-S-Gowda closed 5 months ago

Disha-S-Gowda commented 6 months ago

Hello emissary team and CNCF,

We are a group of students from NYU, doing a security self-assessment under CNCF/tag-security. we have tried to understand emissary-ingress, its working and came up with a self-assessment . it will greatly aid us, if you can review it, and provide feedback/suggestions.

Thanks in Advance!!.

Contributors: @Disha-S-Gowda @yashaswi2000 @jcart657 @Saipv17

netlify[bot] commented 6 months ago

Deploy Preview for tag-security canceled.

Name Link
Latest commit e9ffb830db5689bd77f1c618b804ca0d9acf6aff
Latest deploy log https://app.netlify.com/sites/tag-security/deploys/65a7fc643372cf00087e399b
eddie-knight commented 6 months ago

Hi there! I'm just getting started looking at your pull request, and I noticed the DCO check is failing.

You can look at the checks section of the PR (I believe it should always be below the last comment) and look for a red X highlighting the failed check. In this case, you can click Details for more information about how to get that check passing.

Screenshot 2023-12-08 at 8 35 18 AM
yashaswi2000 commented 6 months ago

Hi @eddie-knight, thanks for your initial review. we have cleaned up the commit history and removed the template text as you pointed out, name change to the file. Please let me know if you have any more comments in the future. Thanks!

yashaswi2000 commented 6 months ago

Hi @ragashreeshekar, thanks for your review. we addressed the changes suggested by you. please let us know any further comments or suggestions you have. also, it's not showing to me that the base branch is out of sync, and showing "Able to merge" so a bit confused as to what you are referring to.