cncf / toc

⚖️ The CNCF Technical Oversight Committee (TOC) is the technical governing body of the CNCF Foundation.
https://cncf.io
1.67k stars 632 forks source link

[Incubation] Kubescape incubation application #1291

Open craigbox opened 6 months ago

craigbox commented 6 months ago

Kubescape incubation application

Project points of contact:

Incubation Criteria Summary for Kubescape

Adoption Assertion

The project has been adopted by the following organizations in a testing and integration or production capacity:

See ADOPTERS.

Owing to the nature of security software, only a small subset are willing to be listed.

Our download numbers suggest Kubescape is used by thousands of end users, either directly, or as customers of commercial security solutions such as ARMO Platform and Jit.

Application Process Principles

Required

Governance and Maintainers

Required

Contributors and Community

Required

Engineering Principles

Required

Security

Required

Ecosystem

Required

PushkarJ commented 4 months ago

@craigbox as part of this task:

TAG provides insight/recommendation of the project in the context of the landscape

Can you please submit a "Presentation" Issue in https://github.com/cncf/tag-security so we can dive deeper into the project and give feedback ?

craigbox commented 4 months ago

@slashben will lead that: if you have a chance, please do refer back to the linked meetings for occasions where he has presented Kubescape in the past.

TheFoxAtWork commented 2 months ago

Hello! I'm your TOC Sponsor for Kubescape. I'll be closing cncf/toc#1209 in favor of this application but will refer back to the previous as needed.

What happens next:

TheFoxAtWork commented 2 months ago

cncf/toc#1209 has been closed: https://github.com/cncf/toc/pull/1209#issuecomment-2218656495

slashben commented 2 months ago

Hey @TheFoxAtWork ,

We are super excited 😄

We have discussed who should lead this. We decided that the main point of contact would be @matthyx and myself. @craigbox will be CC-ed on the process, but he won't lead the process due to scheduling complexities.

I will share with you the e-mail addresses.

TheFoxAtWork commented 2 months ago

@slashben Thank you!
The initial evaluation of the project has been completed. No items were found that could not be quickly resolved by the project (security self-assessment is the primary area, I'll request a status update on this in our kick-off). I've sent a Poll to find time for kick off meeting and discuss expectations.

TheFoxAtWork commented 2 months ago

Kick off meeting schedule for July 23rd 2024. Invites have been sent.

TheFoxAtWork commented 1 month ago

Kick off meeting was held on July 23rd 2024. Received adopters listing from the project August 5th 2024. I've begun Due Diligence and have begun making notes of items needing updates/ corrections in the kick-off and ongoing notes document shared with the project maintainers. I've advised the project of my upcoming limited availability due to upcoming conference talks and travel between now and October. I'll begin reaching out for adopter interview scheduling when i am further along with the DD.

TheFoxAtWork commented 3 weeks ago

I am parallelizing adopter interviews while i conduct the due diligence as adopters report availability for interviews.

I've completed 1 adopter interview thus far and am re-engaging with others to resume scheduling

TheFoxAtWork commented 3 weeks ago

Still working through the DD - re-emailed adopters to check in on approvals to conduct the interview, reached out to more, put out a call for adopters with the TAB. (Security projects usually have this difficulty)

TheFoxAtWork commented 2 days ago

Another Adopter is scheduled in October, I've reached out to one who appeared interested and allowable, but needed to follow up again with scheduling.

It is my hope that if i can get the third one scheduled, I'll have all the needed interviews and can wrap up the evaluation shortly after.

matthyx commented 2 days ago

Another Adopter is scheduled in October, I've reached out to one who appeared interested and allowable, but needed to follow up again with scheduling.

It is my hope that if i can get the third one scheduled, I'll have all the needed interviews and can wrap up the evaluation shortly after.

This is awesome 👍 thanks so much for your work Emily, we're blessed for having you!