diff --git a/.github/ISSUE_TEMPLATE/template-graduation-application.md b/.github/ISSUE_TEMPLATE/template-graduation-application.md index 75f3c793b..06cca99f3 100644 --- a/.github/ISSUE_TEMPLATE/template-graduation-application.md +++ b/.github/ISSUE_TEMPLATE/template-graduation-application.md @@ -69,10 +69,14 @@ Completion of this due diligence document, resolution of concerns raised, and pr ## Governance and Maintainers -Note: this section may be augmented by the completion of a Governance Review from the Project Reviews subproject. +Note: this section may be augmented by the completion of a Governance Review from the Project Reviews subproject if completed as a suggested item prior to application. ### Suggested +- [ ] **Complete a Governance Review with the Project Reviews subproject** + + + - [ ] **Governance has continuously been iterated upon by the project as a result of their experience applying it, with the governance history demonstrating evolution of maturity alongside the project's maturity evolution.** @@ -217,10 +221,14 @@ Note: this section may be augmented by the completion of a Governance Review fro ## Security -Note: this section may be augmented by a joint-assessment performed by TAG Security and Compliance. +Note: this section may be augmented by a joint-assessment performed by TAG Security and Compliance if completed as a suggested item prior to application. ### Suggested +- [ ] **Complete a [joint security assessment](https://tag-security.cncf.io/community/assessments/guide/#joint-assessment) with TAG Security and Compliance** + + + - [ ] **Achieving OpenSSF Best Practices silver or gold badge.** diff --git a/.github/ISSUE_TEMPLATE/template-incubation-application.md b/.github/ISSUE_TEMPLATE/template-incubation-application.md index 227a90f11..1726236d5 100644 --- a/.github/ISSUE_TEMPLATE/template-incubation-application.md +++ b/.github/ISSUE_TEMPLATE/template-incubation-application.md @@ -69,10 +69,14 @@ Completion of this due diligence document, resolution of concerns raised, and pr ## Governance and Maintainers -Note: this section may be augmented by the completion of a Governance Review from the Project Reviews subproject. +Note: this section may be augmented by the completion of a Governance Review from the Project Reviews subproject if completed as a suggested item prior to application. ### Suggested +- [ ] **Complete a Governance Review with the Project Reviews subproject** + + + - [ ] **Governance has continuously been iterated upon by the project as a result of their experience applying it, with the governance history demonstrating evolution of maturity alongside the project's maturity evolution.** @@ -209,13 +213,15 @@ Note: this section may be augmented by the completion of a Governance Review fro ## Security +Note: this section may be augmented by a joint-assessment performed by TAG Security and Compliance if completed as a suggested item prior to application. + ### Suggested -N/A +- [ ] **Complete a joint security assessment with TAG Security and Compliance** -### Required + -Note: this section may be augmented by a joint-assessment performed by TAG Security and Compliance. +### Required - [ ] **Clearly defined and discoverable process to report security issues.** diff --git a/operations/toc-templates/template-dd-pr-graduation.md b/operations/toc-templates/template-dd-pr-graduation.md index fda61816d..abd13aa13 100644 --- a/operations/toc-templates/template-dd-pr-graduation.md +++ b/operations/toc-templates/template-dd-pr-graduation.md @@ -52,10 +52,14 @@ Completion of this due diligence document, resolution of concerns raised, and pr ## Governance and Maintainers -Note: this section may be augmented by the completion of a Governance Review from the Project Reviews subproject. +Note: this section may be augmented by the completion of a Governance Review from the Project Reviews subproject if completed as a suggested item prior to application. ### Suggested +- [ ] **Complete a Governance Review with the Project Reviews subproject** + + + - [ ] **Governance has continuously been iterated upon by the project as a result of their experience applying it, with the governance history demonstrating evolution of maturity alongside the project's maturity evolution.** @@ -204,7 +208,8 @@ N/A ## Security -Note: this section may be augmented by a joint-assessment performed by TAG Security and Compliance. +Note: this section may be augmented by a joint-assessment performed by TAG Security and Compliance if completed as a suggested item prior to application. + ### Suggested @@ -212,6 +217,10 @@ Note: this section may be augmented by a joint-assessment performed by TAG Secur +- [ ] **Complete a joint security assessment with TAG Security and Compliance** + + + ### Required - [ ] **Clearly defined and discoverable process to report security issues.** diff --git a/operations/toc-templates/template-dd-pr-incubation.md b/operations/toc-templates/template-dd-pr-incubation.md index 23c10b534..836992fae 100644 --- a/operations/toc-templates/template-dd-pr-incubation.md +++ b/operations/toc-templates/template-dd-pr-incubation.md @@ -50,10 +50,14 @@ Completion of this due diligence document, resolution of concerns raised, and pr ## Governance and Maintainers -Note: this section may be augmented by the completion of a Governance Review from the Project Reviews subproject. +Note: this section may be augmented by the completion of a Governance Review from the Project Reviews subproject if completed as a suggested item prior to application. ### Suggested +- [ ] **Complete a Governance Review with the Project Reviews subproject** + + + - [ ] **Governance has continuously been iterated upon by the project as a result of their experience applying it, with the governance history demonstrating evolution of maturity alongside the project's maturity evolution.** @@ -190,13 +194,15 @@ Note: this section may be augmented by the completion of a Governance Review fro ## Security +Note: this section may be augmented by a joint-assessment performed by TAG Security and Compliance if completed as a suggested item prior to application. + ### Suggested -N/A +- [ ] **Complete a joint security assessment with TAG Security and Compliance** -### Required + -Note: this section may be augmented by a joint-assessment performed by TAG Security and Compliance. +### Required - [ ] **Clearly defined and discoverable process to report security issues.**