-
Notifications
You must be signed in to change notification settings - Fork 7
Open
Labels
Description
From CNCF TOC:
KServe Security Self Assessment is available at https://github.com/kserve/community/blob/main/security/self-assessment.md.
TODO for KServe Team:
- Link to the CI/CD generated SBOMs at https://github.com/kserve/community/blob/main/security/self-assessment.md#software-bill-of-materials
- Clarify if the generated docker images are scanned for security vulnerabilities at https://github.com/kserve/community/blob/main/security/self-assessment.md#development-pipeline
- CONTRIBUTING.md should also include information about how to report security vulnerabilties at https://github.com/kserve/community/blob/main/security/self-assessment.md#development-pipeline