Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Proposal for establishing the SIG Security #1333

Closed
jpkrohling opened this issue Jan 11, 2023 · 10 comments
Closed

Proposal for establishing the SIG Security #1333

jpkrohling opened this issue Jan 11, 2023 · 10 comments

Comments

@jpkrohling
Copy link
Member

Based on the discussion from open-telemetry/opentelemetry-collector-releases#207, I would like to propose the creation of the SIG Security. The SIG would be responsible for establishing the patterns to be adopted by other SIGs and repositories, as well as serve as a go-to place for security inquiries.

Initially, the SIG would have @cpanato and me, and we are open to having anyone else who'd want to join us.

This would NOT be a security response team (although we can kick off a discussion around that if needed).

@jpkrohling
Copy link
Member Author

@reyang volunteered to be a sponsor for this proposal.

@reyang
Copy link
Member

reyang commented Jan 12, 2023

@reyang volunteered to be a sponsor for this proposal.

Yup 👍

@cpanato
Copy link

cpanato commented Jan 12, 2023

thanks for the trust and +1

@arminru
Copy link
Member

arminru commented Jan 25, 2023

+1 on this initiative!

It would be great if the security of our Github actions/workflows/automations/secrets and repo settings could be covered there as well.
Only if they are solid, signed binaries like the ones produced by open-telemetry/opentelemetry-collector-releases#207 can actually be considered trustworthy.

@cpanato
Copy link

cpanato commented Jan 30, 2023

definitely we can work on those things as well

@reyang
Copy link
Member

reyang commented Jan 31, 2023

@jpkrohling consider borrow from open-telemetry/opentelemetry-specification#3112 PR description.

@jpkrohling
Copy link
Member Author

I had too many things on my plate and couldn't follow up. I'll likely be able to give more attention to this and make a formal proposal for this SIG following @reyang's suggestion.

@cartersocha
Copy link
Contributor

I'm willing to help out @jpkrohling

@cartersocha
Copy link
Contributor

I created a draft issue @cpanato @jpkrohling

#1454

@jpkrohling
Copy link
Member Author

SIG is there for a while now, closing.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants