Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add Catena-X Security Group (READ ONLY) #46

Open
SSIRKC opened this issue Jan 12, 2024 · 7 comments
Open

Add Catena-X Security Group (READ ONLY) #46

SSIRKC opened this issue Jan 12, 2024 · 7 comments

Comments

@SSIRKC
Copy link

SSIRKC commented Jan 12, 2024

Hi guys,

as mentioned in the office hours we currently have no committers by the security team that CAN SEE the security advisories due to view rights. To solve this we would like to be added to each product in the Tractus-X repo with READ rights.

Our Request To EF:
To achieve this efficientely it was suggested to have a SIG-Security group to be added as a TEAM in the Tractus-X repository.
Otherwise each product owner has to add each one of us with view rights to his product repository.

It would be great if you can create such a group as EF also has a security group with view rights.

Kind regards
Kristian Cicka

@SebastianBezold
Copy link
Contributor

ping @netomi: Could you maybe have a look at this and clarify, if the EF would do something like that?

@netomi
Copy link
Contributor

netomi commented Jan 12, 2024

we could create a separate team for the organization for all security team members and add that team as security managers for the organization. For some projects we added all committers as security managers, but that would not work for tractusx but the separate team that is anyway responsible for that would make sense.

@SebastianBezold
Copy link
Contributor

Ok sounds reasonable to me. What do you think @SSIRKC?
@netomi, how would on- and offboarding members to this new team work? Is it a PR done by a committer to the otterdog config, or would that happen via Help Desk ticket?

@netomi
Copy link
Contributor

netomi commented Jan 12, 2024

yeah, creating and updating the team should go via HelpDesk for visibility.

@SSIRKC
Copy link
Author

SSIRKC commented Jan 12, 2024

Hi @SebastianBezold , @netomi ,

yes that would be great to have another team/group for the Catena-X security team.
Any other solution would be alot of effort. How can this be created @netomi ?

@netomi
Copy link
Contributor

netomi commented Jan 12, 2024

Open a HelpDesk ticket and list the names of people that should be part of that team + some approval from a project lead.

@SSIRKC
Copy link
Author

SSIRKC commented Jan 15, 2024

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants