A part of achieving a CII Badge involves in setting up a security disclosure process, which is a great practice for all open source projects to have. However, not all security disclosure processes are tested so the TOC is considering the requirement moving forward to have CNCF projects go through a third party security audit which helps test the security disclosure process. |
||
---|---|---|
.. | ||
due-diligence-guidelines.md | ||
election-schedule.md | ||
graduation_criteria.adoc | ||
project_proposals.adoc | ||
sandbox.md | ||
sandbox.png |