Skip to content

Commit

Permalink
some link changes
Browse files Browse the repository at this point in the history
Signed-off-by: Eddie Knight <knight@linux.com>
  • Loading branch information
eddie-knight committed Jan 29, 2025
1 parent be3658f commit af43aac
Show file tree
Hide file tree
Showing 3 changed files with 13 additions and 13 deletions.
8 changes: 4 additions & 4 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Security Technical Advisory Group

![Cloud Native Security Logo](/community/resources/design/logo/cloud-native-security-horizontal-darkmodesafe.svg)
![Cloud Native Security Logo](resources/tag/logo/cloud-native-security-horizontal-darkmodesafe.svg)

## Quick links

Expand Down Expand Up @@ -32,12 +32,12 @@ Below is a list of publications by TAG Security. For a comprehensive collection
| [Catalog of Supply Chain Compromises](community/catalog/compromises) | November 2019 - Present |
| [Software Supply Chain Best Practices](community/working-groups/supply-chain-security/supply-chain-security-paper/CNCF_SSCP_v1.pdf) | May, 2021 |
| [Evaluating your Supply Chain Security](community/working-groups/supply-chain-security/supply-chain-security-paper/secure-supply-chain-assessment.md) | May, 2021 |
| [Cloud Native Security Lexicon](community/resources/security-lexicon/cloud-native-security-lexicon.md) | August, 2021 |
| [Cloud Native Security Whitepaper](community/resources/security-whitepaper/v2/CNCF_cloud-native-security-whitepaper-May2022-v2.pdf) | May, 2022 |
| [Cloud Native Security Lexicon](publications/security-lexicon/cloud-native-security-lexicon.md) | August, 2021 |
| [Cloud Native Security Whitepaper](publications/security-whitepaper/v2/CNCF_cloud-native-security-whitepaper-May2022-v2.pdf) | May, 2022 |
| [Cloud Native Security Controls Catalog](community/working-groups/controls/phase-one-announcement.md) | May, 2022 |
| [Handling Build-time Dependency Vulnerabilities](community/working-groups/archive/policy/overview-policy-build-time-dependency-vulns.md) | June, 2022 |
| [Secure Software Factory: A Reference Architecture to Securing the Software Supply Chain](community/working-groups/supply-chain-security/secure-software-factory/Secure_Software_Factory_Whitepaper.pdf) | May, 2022 |
| [Secure Defaults](community/resources/security-whitepaper/secure-defaults-cloud-native-8.md) | February, 2022 |
| [Secure Defaults](publications/security-whitepaper/secure-defaults-cloud-native-8.md) | February, 2022 |
| [Open and Secure - A Manual for Practicing Threat Modeling to Assess and Fortify Open Source Security](community/assessments/Open_and_Secure.pdf) | November, 2023 |

## Governance
Expand Down
4 changes: 2 additions & 2 deletions community/assessments/projects/kubescape/self-assessment.md
Original file line number Diff line number Diff line change
Expand Up @@ -316,7 +316,7 @@ In addition, Kubescape has a Fix Disclosure Process that includes disclosing for

## Incident Response

There is a template for incident response for reference [here](https://github.com/cncf/tag-security/blob/main/community/resources/project-resources/templates/incident-response.md)
There is a template for incident response for reference [here](https://github.com/cncf/tag-security/blob/mainresources/tag/project/templates/incident-response.md)

## Appendix

Expand All @@ -329,4 +329,4 @@ There is a template for incident response for reference [here](https://github.co

The Kubescape project is continuously improving its practices based on the OpenSSF recommendations, see [Scorecard Results](https://securityscorecards.dev/viewer/?uri=github.com/kubescape/kubescape) and [Best Practices Badge](https://www.bestpractices.dev/en/projects/6944)

<!-- cSpell:ignore Grype Inspektor -->
<!-- cSpell:ignore Grype Inspektor -->
14 changes: 7 additions & 7 deletions community/publications/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,18 +6,18 @@ This document lists all the publications and resources that TAG Security has pro
|-------------|--------------|--------|------|
| **Cloud Native Security Controls Catalog** | Mapping of Cloud Native Security Whitepaper and Software Supply Chain Best Practices Paper to NIST SP800-53r5 | Markdown | [Link](/community/working-groups/controls/phase-one-announcement.md) |
| | | Spreadsheet | [Link](https://docs.google.com/spreadsheets/d/1GUohOTlLw9FKUQ3O23X7ypvJLXN-B3veJGe6YE6JYfU/edit?usp=sharing) |
| **Cloud Native Security Lexicon** | Standardization of terminologies specific to Cloud Native Security | Markdown | [Link](/community/resources/security-lexicon/cloud-native-security-lexicon.md) |
| **Cloud Native Security Whitepaper** | Information about building, distributing, deploying, and running secure cloud native capabilities | Markdown (v2) | [Link](/community/resources/security-whitepaper/v2/cloud-native-security-whitepaper.md) |
| | | PDF (v2) | [Link](/community/resources/security-whitepaper/v2/CNCF_cloud-native-security-whitepaper-May2022-v2.pdf) |
| **Cloud Native Security Lexicon** | Standardization of terminologies specific to Cloud Native Security | Markdown | [Link](/publications/security-lexicon/cloud-native-security-lexicon.md) |
| **Cloud Native Security Whitepaper** | Information about building, distributing, deploying, and running secure cloud native capabilities | Markdown (v2) | [Link](/publications/security-whitepaper/v2/cloud-native-security-whitepaper.md) |
| | | PDF (v2) | [Link](/publications/security-whitepaper/v2/CNCF_cloud-native-security-whitepaper-May2022-v2.pdf) |
| | | Audio (v1) | [Link](https://soundcloud.com/user-769472014/sets/cncf-tag-security-cloud-native-security-whitepaper-version-v1) |
| | **Translations** | | |
| | | Portuguese (v1) | [Link](/community/resources/security-whitepaper/v1/cloud-native-security-whitepaper-brazilian-portugese.md) |
| | | Chinese (v2) | [Link](/community/resources/security-whitepaper/v2/CNCF_cloud-native-security-whitepaper-cn-Sept2023-v2.pdf) |
| | | Portuguese (v1) | [Link](/publications/security-whitepaper/v1/cloud-native-security-whitepaper-brazilian-portugese.md) |
| | | Chinese (v2) | [Link](/publications/security-whitepaper/v2/CNCF_cloud-native-security-whitepaper-cn-Sept2023-v2.pdf) |
| **Open and Secure - A Manual for Practicing Threat Modeling to Assess and Fortify Open Source Security** | Guide for assessing and understanding the security of open source software projects | PDF | [Link](/community/assessments/Open_and_Secure.pdf) |
| **Policy** | | | |
| | Formal Verification for Policy Configurations | Markdown | [Link](/community/working-groups/archive/policy/overview-policy-formal-verification.md) |
| | Handling build-time dependency vulnerabilities | Markdown | [Link](/community/working-groups/archive/policy/overview-policy-build-time-dependency-vulns.md) |
| **Secure Defaults: Cloud Native 8** | | Markdown | [Link](/community/resources/security-whitepaper/secure-defaults-cloud-native-8.md) |
| **Secure Defaults: Cloud Native 8** | | Markdown | [Link](/publications/security-whitepaper/secure-defaults-cloud-native-8.md) |
| **Security Assessments** | Assessments of several CNCF projects | | |
| | Buildpacks | Markdown | [Link](/community/assessments/projects/buildpacks) |
| | Cloud Custodian | Markdown | [Link](/community/assessments/projects/custodian) |
Expand All @@ -35,4 +35,4 @@ This document lists all the publications and resources that TAG Security has pro
| | Secure Software Factory | Markdown | [Link](/community/working-groups/supply-chain-security/secure-software-factory/secure-software-factory.md) |
| | | PDF | [Link](/community/working-groups/supply-chain-security/secure-software-factory/Secure_Software_Factory_Whitepaper.pdf) |
| | Catalog of Supply Chain Compromises | Markdown | [Link](/community/catalog/compromises) |
| **Use Cases & Personas** | List of use cases to enable secure access, policy control, and safety for users of cloud native technology | Markdown | [Link](/community/resources/usecase-personas/README.md) |
| **Use Cases & Personas** | List of use cases to enable secure access, policy control, and safety for users of cloud native technology | Markdown | [Link](/publications/usecase-personas/README.md) |

0 comments on commit af43aac

Please sign in to comment.