Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Slam 2023 Participation #296

Closed
eddie-knight opened this issue Oct 16, 2023 · 4 comments
Closed

Security Slam 2023 Participation #296

eddie-knight opened this issue Oct 16, 2023 · 4 comments
Assignees
Labels

Comments

@eddie-knight
Copy link

Hello ocm community!

In case you missed it, last week was the kickoff for the month-long Cloud Native Security Slam! You can read more about the event and find the kickoff webinar recording here.

In the kickoff last week, it was announced that there are 5 event badges that projects can pursue. There will be swag prizes and a $100 gift card awarded for the first 200 badges that are competed— that's up to $500 per project!

To help with work prioritization, we completed a survey of CNCF end users across multiple industries, including Construction, Cybersecurity, Aerospace & Defense, Game Development & Consumer Services, Consulting, and Nuclear.

Through this survey, end users have identified their interest in seeing security improvements to the projects they use. We've asked them to share which Security Slam goals are most interesting to them— and we've compiled the results in a hope that this will help your prioritization during the upcoming event.

While some users have not authorized us to share their name, we've still included their responses in our calculation for you. We CAN tell you that the ocm responses included Epic Games.

After calculating the responses according to the interest-weight, we've found these to be the most interesting things that ocm end users would like to see, from the five possible Security Slam badges.

  1. The Mechanizer
  2. The Defender
  3. The Cleaner

You can read more about the success metrics and find resources to help you achieve them here.

Join us in the #security-slam channel on the CNCF Slack to ask questions and get help from the community!

@zhujian7
Copy link
Member

@eddie-knight Thank you for telling us about this opportunity, I will assign this to myself
/assign

@zhujian7
Copy link
Member

zhujian7 commented Oct 19, 2023

There already is a CLOMonitor dashboard: https://clomonitor.io/projects/cncf/ocm

CLOMonitor report summary

Summary for the ocm repo:

CLOMonitor report

Summary

Repository: ocm
URL: https://github.com/open-cluster-management-io/ocm
Checks sets: CODE
Score: 74

Checks passed per category

Category Score
Documentation 100%
License 75%
Best Practices 63%
Security 63%
Legal n/a

Checks

Documentation [100%]

License [75%]

Best Practices [63%]

Security [63%]

For more information about the checks sets available and how each of the checks work, please see the CLOMonitor's documentation.


I will try to bring the score to 100%, and will also update the summary in this comment if there is any progress.

@eddie-knight
Copy link
Author

Hey @zhujian7, did you get a chance to sign up OCM to qualify for Slam prizes?

Also, we added a getting started guide if you want to check to see whether that's helpful for you

Copy link

github-actions bot commented Mar 2, 2024

This issue is stale because it has been open for 120 days with no activity. After 14 days of inactivity, it will be closed. Remove the stable label to prevent this issue from being closed.

@github-actions github-actions bot added the Stale label Mar 2, 2024
mprahl pushed a commit to mprahl/OCM that referenced this issue Mar 14, 2024
Bumps [github.com/emicklei/go-restful](https://github.com/emicklei/go-restful) from 2.9.5+incompatible to 2.16.0+incompatible.
- [Release notes](https://github.com/emicklei/go-restful/releases)
- [Changelog](https://github.com/emicklei/go-restful/blob/v3/CHANGES.md)
- [Commits](emicklei/go-restful@v2.9.5...v2.16.0)

---
updated-dependencies:
- dependency-name: github.com/emicklei/go-restful
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
Status: Done
Development

No branches or pull requests

2 participants