diff --git a/ci/spelling-config.json b/ci/spelling-config.json index a89f2963c..8744fc9bc 100644 --- a/ci/spelling-config.json +++ b/ci/spelling-config.json @@ -26,6 +26,7 @@ "cisecurity", "CISO", "cloudcustodian", + "CLOMonitor", "CMMC", "CNCF", "CNSC", diff --git a/project-resources/moving-levels-review-template.md b/project-resources/moving-levels-review-template.md index a160e5b7d..e5d774b1b 100644 --- a/project-resources/moving-levels-review-template.md +++ b/project-resources/moving-levels-review-template.md @@ -1,4 +1,4 @@ -# Template for TAG recommendation to TOC +# TAG recommendation to TOC ## Project Overview @@ -8,13 +8,17 @@ What ecosystem adoption has the project seen? ### Past TOC Reviews -How has the project addressed comments from previous reviews (incubation if graduation, sandbox if incubating, etc)? +If the project has undergone a previous TAG or TOC review, how has the project addressed comments from those reviews? ## Security Reviews ### TAG Security Assessments -Has the project completed a TAG Security Self-Assessment and/or Joint Assessment? If yes, please add a link and discuss how this has impacted their security posture. +If applying for incubation, has the project completed a self-assessment? _(If not, the TAG cannot provide any recommendation to the TOC.)_ + +If applying for graduation, has the project completed a joint assessment? _(If not, the TAG cannot provide any recommendation to the TOC.)_ + +If yes to either, were there any findings or recommendations that the project has addressed or added to a roadmap? Please provide links if applicable. ### Security Audit @@ -24,14 +28,34 @@ Has the project completed an external security audit? If yes, how have they addr ### Metrics -Which security best practices does the project follow (for example CNCF best practices badge, OpenSSF Best Practices, CLO monitor), and how does it rate by these metrics? +Which security best practices does the project follow (for example CNCF best practices badge, OpenSSF Best Practices, LFX Insights, CLOmonitor)? + +How does it rate by these metrics? Please provide links if applicable. ### Static Analysis -Does the project perform static analysis? +Does the project perform static analysis such as SAST or SCA? Please provide links if applicable. ## Sub-project Considerations +### Role of Sub-projects in the Project Ecosystem + +Does your project have sub-projects? If so, how do they interact with the main project? + +What is the maturity and adoption of each sub-project? + +Please provide links to any sub-projects that are compiled into the main project. + +Please provide links to any other sub-projects that are currently intended for end-user adoption. + +### Security Posture of Sub-projects + If the project has sub-projects, how does their security posture compare to the base project? ## TAG Recommendation to the TOC + + + + + +