cncf / toc

⚖️ The CNCF Technical Oversight Committee (TOC) is the technical governing body of the CNCF Foundation.
https://cncf.io
1.68k stars 632 forks source link

ENH:proposals: add in-toto graduation proposal #1162

Open SantiagoTorres opened 1 year ago

SantiagoTorres commented 1 year ago

This is a formal proposal for the graduation of the in-toto project.

in-toto, an open-source project that joined CNCF as a sandbox project in August 2019, and incubation in March 2022. Since then, in-toto has experienced a remarkable degree of adoption within various ecosystems and usecases. These include cases such as GitHub's, Gitlab's and Tekton among others. Due to this, we are confident that in-toto is ready to graduate.

Supporting Documents

link to graduation DD document

Incubation Documents

link to incubation PR incubation DD

P.S. I was holding back on the former proposal because there were going to be changes to the process, but seeing other projects are moving forward as well I'd rather leave a formal paper trail

lukehinds commented 1 year ago

nb +1 !

adityasaky commented 1 year ago

Very excited to see this happen!

JustinCappos commented 1 year ago

nb +1. This is long overdue!!!

trishankatdatadog commented 1 year ago

+1

giphy

mnm678 commented 1 year ago

nb +1

tannerjones4075 commented 1 year ago

It is great to see the progress and see the impact of in-toto thus far. Great things to come!

evan2645 commented 1 year ago

nb +1 🎉

joshuagl commented 1 year ago

nb +1 🎓

in-toto is not only a great system, it is also a frequently cited inspiration for other systems, defines standard formats that multiple systems implement, and benefits from multiple quality implementations.

lukpueh commented 1 year ago

nb +1

As one of the original in-toto core team members, I can attest that a lot of thought has gone into the design and development of the system. And I am very excited to see its impact grow in the supply chain security ecosystem. Graduation seems appropriate.

marcelamelara commented 1 year ago

+1 for graduation of in-toto!!

colek42 commented 1 year ago

+1

kommendorkapten commented 1 year ago

+1

idunbarh commented 1 year ago

+1 as a relative new comer to the project and I've been really impressed by the maintainers and community. Absolutely supportive of project graduation!

alanssitis commented 1 year ago

+1 :heart:

06kellyjac commented 1 year ago

+1

matglas commented 6 months ago

+1

linsun commented 5 months ago

Hi @SantiagoTorres, I'll be reviewing your proposal soon! Excited to see so much support of in-toto here!

kairoaraujo commented 5 months ago

+1

linsun commented 4 months ago

Some update - met with @SantiagoTorres last week and walked him through the new process along with expected timeline. Raised a few issues with @SantiagoTorres and started working on putting DD doc together. From our discussion, @SantiagoTorres has already setup a review with TAG-security, see https://github.com/cncf/tag-security/issues/1290.

I'm traveling for this and next 2 weeks unfortunately, will have limited bandwidth but will make progress whenever I can.

cc @TheFoxAtWork @nikhita FYI

anvega commented 3 months ago

TAG Security has conducted a thorough review of the in-toto project as part of its consideration for CNCF graduation. Based on our assessment, we find:

in-toto presents as a mature, well designed security project that has made significant strides toward graduation. Key points supporting this include:

Opportunities for further development:

In conclusion, in-toto demonstrates the characteristics of a graduated level CNCF project, particularly in terms of security. Its wide adoption, successful response to security audits, and overall mature security posture make it a strong candidate for graduation. The project serves as an exemplar of security design in the ecosystem.

linsun commented 3 months ago

Thank you @anvega for the detailed note, glad the review went very well and in-toto continues to demonstrate the characteristics of a graduated level CNCF project.

Update: @SantiagoTorres is working on getting me interviewer lists and also answering some questions I had while preparing the DD doc.

linsun commented 2 months ago

Still working on @SantiagoTorres on the proposal doc, also have 1 interviewee scheduled this week!

linsun commented 1 month ago

Synched with @SantiagoTorres today, DD 80% done, a few todo items remaining but nothing blocking. Adopter 1 interview has been done and uploaded to CNCF TOC folder, and adopter 2 interview is being rescheduled.

trishankatdatadog commented 1 month ago

Synched with @SantiagoTorres today, DD 80% done, a few todo items remaining but nothing blocking. Adopter 1 interview has been done and uploaded to CNCF TOC folder, and adopter 2 interview is being rescheduled.

Anything else the in-toto Steering Committee can help with here, please?

jberkus commented 1 month ago

Someone needs to submit at Governance Review request for In-toto.

trishankatdatadog commented 1 month ago

Someone needs to submit at Governance Review request for In-toto.

Got it. Where and how, please?

TheFoxAtWork commented 1 month ago

https://github.com/cncf/tag-contributor-strategy/issues/new?template=governance-review-request.yaml

linsun commented 1 month ago

Thanks for the reminder @jberkus and @TheFoxAtWork for the link! @trishankatdatadog and @SantiagoTorres pls let us know when this is submitted, thanks!

jberkus commented 3 weeks ago

Ping, we still don't have a gov review request.

trishankatdatadog commented 3 weeks ago

Ping, we still don't have a gov review request.

Sorry for the delay --- was going to send today! Let me send it off in a bit...

trishankatdatadog commented 3 weeks ago

Ping, we still don't have a gov review request.

Sorry for the delay --- was going to send today! Let me send it off in a bit...

Done! Please let us know if you need any other information there.

linsun commented 3 weeks ago

Still working on @SantiagoTorres on the proposal doc, waiting for a few final items from @SantiagoTorres! 2 adopter interviews are finished and working on getting the 3rd interviewee scheduled!