-
Notifications
You must be signed in to change notification settings - Fork 665
Update templates to suggest a joint security assessment and governance review #1929
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Update templates to suggest a joint security assessment and governance review #1929
Conversation
Signed-off-by: Jeremy Rickard <jeremyrrickard@gmail.com>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM - moved the note up to the top and added the reference as suggested. I'd hate for a project to do a joint-assessment and a TOC member not use it because we weren't explicit.
| <!-- (TOC Evaluation goes here) --> | ||
|
|
||
| ## Security | ||
|
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Note: this section may be augmented by a joint-assessment performed by TAG Security and Compliance if completed as a suggested item prior to application.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
"Suggested item within the application prior to submission"
Signed-off-by: Jeremy Rickard <jeremyrrickard@gmail.com>
Co-authored-by: Emily Fox <33327273+TheFoxAtWork@users.noreply.github.com> Signed-off-by: Jeremy Rickard <jeremyrrickard@gmail.com>
Signed-off-by: Jeremy Rickard <jeremyrrickard@gmail.com>
TheFoxAtWork
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks good - now just need to update the issue templates :) the issue templates should have the link to the project reviews process for projects applying to know exactly where to get that.
|
|
||
| ## Security | ||
| Note: this section may be augmented by a joint-assessment performed by TAG Security and Compliance if completed as a suggested item prior to application. | ||
| Note: this section may be augmented by a joint-assessment performed by TAG Security and Compliance. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| Note: this section may be augmented by a joint-assessment performed by TAG Security and Compliance. |
Signed-off-by: Jeremy Rickard <jeremyrrickard@gmail.com>
TheFoxAtWork
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Lgtm thank u!!
angellk
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
language is ambiguous - please clarify!
| ## Governance and Maintainers | ||
|
|
||
| Note: this section may be augmented by the completion of a Governance Review from the Project Reviews subproject. | ||
| Note: this section may be augmented by the completion of a Governance Review from the Project Reviews subproject if completed as a suggested item prior to application. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Please be more explicit on who is suggesting the Governance Review
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
"Suggested item within the application prior to submission" -- we may need to review overall language in the application to reduce confusion for multiple geos/cultures
| ## Security | ||
|
|
||
| Note: this section may be augmented by a joint-assessment performed by TAG Security and Compliance. | ||
| Note: this section may be augmented by a joint-assessment performed by TAG Security and Compliance if completed as a suggested item prior to application. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
"Suggested item within the application prior to submission"
| ## Governance and Maintainers | ||
|
|
||
| Note: this section may be augmented by the completion of a Governance Review from the Project Reviews subproject. | ||
| Note: this section may be augmented by the completion of a Governance Review from the Project Reviews subproject if completed as a suggested item prior to application. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
"Suggested item within the application prior to submission"
| ## Governance and Maintainers | ||
|
|
||
| Note: this section may be augmented by the completion of a Governance Review from the Project Reviews subproject. | ||
| Note: this section may be augmented by the completion of a Governance Review from the Project Reviews subproject if completed as a suggested item prior to application. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
"Suggested item within the application prior to submission"
| ## Security | ||
|
|
||
| Note: this section may be augmented by a joint-assessment performed by TAG Security and Compliance. | ||
| Note: this section may be augmented by a joint-assessment performed by TAG Security and Compliance if completed as a suggested item prior to application. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
"Suggested item within the application prior to submission"
| ## Governance and Maintainers | ||
|
|
||
| Note: this section may be augmented by the completion of a Governance Review from the Project Reviews subproject. | ||
| Note: this section may be augmented by the completion of a Governance Review from the Project Reviews subproject if completed as a suggested item prior to application. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
"Suggested item within the application prior to submission"
|
|
||
| ## Security | ||
|
|
||
| Note: this section may be augmented by a joint-assessment performed by TAG Security and Compliance if completed as a suggested item prior to application. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
"Suggested item within the application prior to submission"
Per discussion at the 10/21/2025 TOC meeting, this PR updates the DD templates for incubation and graudation to suggest a joint security assessment and a governance review.