kubernetes / committee-security-response

Kubernetes Security Process and Security Committee docs
Apache License 2.0
164 stars 65 forks source link

private-distributors-list: add DaoCloud #180

Open pacoxu opened 1 year ago

pacoxu commented 1 year ago

Actively monitored security email alias for our project: kubernetes-security@daocloud.io

1. Be an actively maintained and CNCF-certified distribution of Kubernetes components. DaoCloud is in the list of https://www.cncf.io/certification/software-conformance/

2. Have a user base not limited to your own organization. Yes

3. Have a publicly verifiable track record up to the present day of fixing security issues.

4. Not be a downstream or rebuild of another distribution. No.

5. Be a participant and active contributor in the community. https://k8s.devstats.cncf.io/d/9/companies-table?orgId=1 DaoCloud ranks 7th in kubernetes community contributions in history, and top 5 if only counting recent 3 years.

Some of the active contributors from DaoCloud in the community:

image

Besides code contributions, we also organized several KCD and KCS in China including KCS China 2023, KCD Beijing 2021&2023, KCD Shanghai 2021&2024, KCD Chengdu 2022 and KCD Shenzhen 2023.

Most of the SIG maintainer talks in KubeCon China 2023 are by DaoClouder, including SIG-Scheduling, SIG-Node, SIG-Instrumentation, Kubespray, KWOK sessions.

BTW, we also try to maintain kube lts version in https://github.com/klts-io/kubernetes-lts for an extended period, and it is open-source and only focus on high value CVEs currently.

6. Accept the Embargo Policy.

Yes.

7. Be willing to contribute back.

yes

8. Have someone already on the list vouch for the person requesting membership on behalf of your distribution. VMware and Microsoft below.

More information can be found in https://github.com/DaoCloud (we add more information about projects that were founded or maintained by DaoClouder there), https://www.daocloud.io/en/ and https://docs.daocloud.io/en/.

pacoxu commented 1 year ago

/cc @puerco @ritazh

neolit123 commented 1 year ago

DaoCloud ranks top 10 in kubernetes community contributions.

+1 to be added

@neolit123 (VMware)

ritazh commented 1 year ago

+1

@ritazh (Microsoft)

pacoxu commented 1 year ago

ack

pacoxu commented 1 year ago

@kubernetes/security-response-committee any update?

enj commented 1 year ago

@kubernetes/security-response-committee any update?

I haven't forgotten, just haven't had time to update distributor requirements.

pacoxu commented 9 months ago

Updated some new approvers/reviewers in Kubernetes Community from DaoCloud.

pacoxu commented 9 months ago

@kubernetes/security-response-committee ACK

k8s-triage-robot commented 6 months ago

The Kubernetes project currently lacks enough contributors to adequately respond to all issues.

This bot triages un-triaged issues according to the following rules:

You can:

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle stale

pacoxu commented 6 months ago

/remove-lifecycle stale still valid in progress

pacoxu commented 6 months ago

I haven't forgotten, just haven't had time to update distributor requirements.

@enj do we have any new requirements for being in the private distributor list? So I can evaluate them and add them to our action items.