Git Product home page Git Product logo

Comments (12)

k8s-ci-robot avatar k8s-ci-robot commented on May 24, 2024

This issue is currently awaiting triage.

SIG Docs takes a lead on issue triage for this website, but any Kubernetes member can accept issues by applying the triage/accepted label.

The triage/accepted label can be added by org members by writing /triage accepted in a comment.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

from website.

sftim avatar sftim commented on May 24, 2024

This is about https://kubernetes.io/docs/reference/issues-security/official-cve-feed/ and the feeds it links to.

/sig security

from website.

sftim avatar sftim commented on May 24, 2024

The CVE feed lists vulnerabilities in Kubernetes' core. I don't think we make that as clear as we could.

from website.

sftim avatar sftim commented on May 24, 2024

/retitle CVE feed doesn't include some vulnerabilities for in-project code

from website.

a-mccarthy avatar a-mccarthy commented on May 24, 2024

@sftim can you clarify here if there is anything actionable on this issue now? or is work dependent on the outcome of the k/k issue you created?

from website.

sftim avatar sftim commented on May 24, 2024

The people working on the KEP could take steps to ensure the upstream feed includes more data; you can't fix this purely by committing to k/website.

However, there's more than one route forward here.

from website.

PushkarJ avatar PushkarJ commented on May 24, 2024

Thanks for the tag @sftim

/priority important-long-term

from website.

k8s-ci-robot avatar k8s-ci-robot commented on May 24, 2024

@PushkarJ: The label(s) priority/important-long-term cannot be applied, because the repository doesn't have them.

In response to this:

Thanks for the tag @sftim

/priority important-long-term

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

from website.

PushkarJ avatar PushkarJ commented on May 24, 2024

Including CVEs outside of k8s core is not in scope at the moment for GA. If this is useful for the community, I would welcome folks to chat with the group who maintains the CVE feed on #sig-security-tooling (Invite yourself from here: https://slack.k8s.io/) and share their intent to contribute to make this happen.

/priority important-longterm

from website.

sftim avatar sftim commented on May 24, 2024

In the meantime, we could clarify in the web page about what's in scope.

from website.

PushkarJ avatar PushkarJ commented on May 24, 2024

@sftim Would it make sense to clarify it as a k/website PR or as part of KEP or both?

from website.

sftim avatar sftim commented on May 24, 2024

Ideally both

from website.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.