Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Does Lyft have any plans to sandbox then donate Clutch to CNCF? #2556

Open
lloydchang opened this issue Jan 26, 2023 · 2 comments
Open

Does Lyft have any plans to sandbox then donate Clutch to CNCF? #2556

lloydchang opened this issue Jan 26, 2023 · 2 comments
Labels
type: enhancement New feature or request

Comments

@lloydchang lloydchang added the type: enhancement New feature or request label Jan 26, 2023
@danielhochman
Copy link
Collaborator

Hi @lloydchang it's something we have talked about and considered. If it would make a difference to any community stakeholders we would be happy to restart that conversation. Ensuring that Clutch is supported and maintained long-term is definitely a goal of ours.

@lloydchang
Copy link
Contributor Author

lloydchang commented Jan 26, 2023

@danielhochman wrote:

Ensuring that Clutch is supported and maintained long-term is definitely a goal of ours.


Thanks @danielhochman

Ultimately, it depends on community interest, as I believe that is important (conceptually-speaking).

This is a good start to having a community discussion.


For a simple example in a different open source project that was not sandboxed with CNCF...

• I reported an error at box/ClusterRunner#457 with a simple fix — Prepend www. to match an SSL certificate, but no one responded yet

• Furthermore, another person reported the same (?) issue 3 years ago at box/ClusterRunner#447

In my humble opinion, when a company or its open source program office cannot perform good stewardship of an open source project... to even reply to simple inquiries, then what seems like a simple fix — Prepend an URL with www. to match an SSL certificate — may never happen. At that point, I believe there seems to be something wrong with a company's open source program office for unknown reasons.

Hypothetically, there could be various reasons, such as:
• Perhaps the open source project has been abandoned without a formal public notice?
• Perhaps the people who had worked on the open source project already left the company?

There are security risks and liabilities in using open source that aren't supported nor maintained.


The idea is that the process from sandboxing to donation to CNCF might mitigate those security risks and liabilities, if given enough funding and support.

For example, in a different open source project that was sandboxed with CNCF...

As Flux is an Incubation project within the Cloud Native Computing Foundation, we were graciously granted a sponsored audit. The primary aim was to assess Flux’s fundamental security posture and to identify next steps in its security story. The audit was commissioned by the CNCF, and facilitated by OSTIF (the Open Source Technology Improvement Fund). ADA Logics was quickly brought into the picture, and spent a month on the audit.
https://www.cncf.io/blog/2021/11/11/flux-security-audit-has-concluded/


Thank you.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
type: enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants