Skip to content

Clarify security team teams, roles and responsibilities #356

Description

@joestringer

There are multiple locations where security teams are managed:

The differences between these groups may not be entirely obvious, but we should look into the organization and repository settings and the team memberships, and clarify the scope for each group as well as who has access to those options.

The related one I think is pretty clear is @cilium/github-sec. This has a smaller, different scope specifically related to ensuring that GitHub workflows are written following security best practices. It's documented in the project-wide reviewers (should probably be called org-wide).

We may want to consider as well how subprojects get access to security reports.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions