open-telemetry / sig-security

Apache License 2.0
7 stars 10 forks source link

Audit repositories for security tools #12

Open codeboten opened 1 year ago

codeboten commented 1 year ago

Get a questionnaire to SIGs in the org asking them what tools are enabled in their repos:

codeboten commented 1 year ago

Start this by documenting what's enabled in the collector repository and producing a form from it

codeboten commented 1 year ago

The following tools are configured for the OpenTelemetry Collector repository:

codeboten commented 1 year ago

Confirmed the same is configured for the OpenTelemetry Collector Contrib repository

JonZeolla commented 1 year ago

We should consider Allstar for monitoring organization-wide policies. The quickstart may meet our needs

svrnm commented 1 year ago

+1 for Allstar

oly-baby commented 1 year ago

GOOD DAY,

I AM AN OUTREACH APPLICANT, CAN I WORK ON THIS

jpkrohling commented 1 year ago

@oly-baby, welcome! Sure, feel free to pick one of the repositories from the list (see the issue description), create an issue on the repository to track the work, and write a report similar to @codeboten's one (a few comments up, here: https://github.com/open-telemetry/sig-security/issues/12#issuecomment-1681251485).

Davidlred commented 1 year ago

Hello guys, i'm an Outreachy applicant, and i'd like to work on one of the issue.

how do i take off ?

jpkrohling commented 1 year ago

@Davidlred, see my previous comment. I'd recommend leaving a comment on the issue you pick, stating that you are working on it. If you need ideas for other tasks, join the #otel-sig-security channel on the CNCF Slack.

sakshi-1505 commented 1 year ago

Hello @jpkrohling , I am picking up one of the issue from the above list.

sakshi-1505 commented 1 year ago

We can use the following tracking issue for opentelemetry-python: https://github.com/open-telemetry/opentelemetry-python/issues/3467

sakshi-1505 commented 1 year ago

We can use the following tracking issue for build-tools: https://github.com/open-telemetry/build-tools/issues/212

sakshi-1505 commented 1 year ago

We can use the following tracking issue for opentelemetry-python-contrib: https://github.com/open-telemetry/opentelemetry-python-contrib/issues/1991

arademm commented 1 year ago

Hello, I'm an Outreachy applicant. I would love to contribute to this project.

jpkrohling commented 1 year ago

@arademm, see my previous comment. I'd recommend leaving a comment on the issue you pick, stating that you are working on it. If you need ideas for other tasks, join the #otel-sig-security channel on the CNCF Slack.

pichlermarc commented 1 month ago

The open-telemetry/opentelemetry-js-api entry can be checked on the list - it's an archived repository, the package that was hosted there was integrated in to https://github.com/open-telemetry/opentelemetry-js :slightly_smiling_face: