cncf-toc/reviews/incubation-harbor.md

4.0 KiB
Raw Blame History

Harbor Incubating Stage Review

Harbor is currently a CNCF sandbox project. Please refer to Harbor's initial sandbox proposal for discussion on Harbor's alignment with the CNCF and details on sandbox requirements.

In the time since being accepted as a sandbox project, Harbor has demonstrated healthy growth and progress.

Incubating Stage Criteria

In addition to sandbox requirements, a project must meet the following criteria to become an incubation-stage project:

Further details of Harbor's growth and progress since entering the sandbox stage as well as use case details from the Harbor community can be found in this slide deck.

Security

Harbor's codebase has been analyzed and reviewed by VMware's internal product security team.

  • Static analysis has been performed on Harbor via gosec
  • Software decomposition via AppCheck, Snyk and retire.js with goal of discovering outdated or vulnerable packages
  • Manual code analysis / review
  • Vulnerability assessment via multiple scanners
  • Completed threat model

In addition to this security work the Harbor maintainers are partnering with the CNCF to schedule a third-party security audit of Harbor.