Skip to content

Clarify security team teams, roles and responsibilities #356

@joestringer

Description

@joestringer

There are multiple locations where security teams are managed:

The differences between these groups may not be entirely obvious, but we should look into the organization and repository settings and the team memberships, and clarify the scope for each group as well as who has access to those options.

The related one I think is pretty clear is @cilium/github-sec. This has a smaller, different scope specifically related to ensuring that GitHub workflows are written following security best practices. It's documented in the project-wide reviewers (should probably be called org-wide).

We may want to consider as well how subprojects get access to security reports.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions