Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Ratify should complete a Tag Security Self Assessment (TSSA) #2035

Open
1 task
akashsinghal opened this issue Jan 16, 2025 · 2 comments
Open
1 task

Ratify should complete a Tag Security Self Assessment (TSSA) #2035

akashsinghal opened this issue Jan 16, 2025 · 2 comments
Labels
enhancement New feature or request
Milestone

Comments

@akashsinghal
Copy link
Collaborator

What would you like to be added?

As part of Ratify sandbox donation, it was recommended by TAG security for Ratify to complete a tag security self assessment and submit for review https://github.com/cncf/tag-security/blob/main/community/assessments/README.md

Anything else you would like to add?

No response

Are you willing to submit PRs to contribute to this feature?

  • Yes, I am willing to implement it.
@akashsinghal akashsinghal added enhancement New feature or request triage Needs investigation labels Jan 16, 2025
@binbin-li
Copy link
Collaborator

Wonder if we should assess the security based on the incoming v2 version or v1. V1 has some design vulnerabilities that require breaking change to fix, probably v2 could make the TSSA look better.

@akashsinghal
Copy link
Collaborator Author

Wonder if we should assess the security based on the incoming v2 version or v1. V1 has some design vulnerabilities that require breaking change to fix, probably v2 could make the TSSA look better.

I agree. v2 makes more sense

@binbin-li binbin-li removed the triage Needs investigation label Feb 13, 2025
@binbin-li binbin-li modified the milestones: v2.0.0-alpha.1, v2.0.0 Feb 13, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants