Skip to content

Commit 257c525

Browse files
authored
Update SECURITY-INSIGHTS (#1111)
1 parent fc9ecb0 commit 257c525

File tree

2 files changed

+46
-35
lines changed

2 files changed

+46
-35
lines changed

.github/SECURITY-INSIGHTS.yml

Lines changed: 45 additions & 34 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,10 @@
1-
# Security Insights 2.0 file https://github.com/ossf/security-insights
2-
# Schema: https://github.com/ossf/security-insights/blob/main/spec/schema.cue
1+
# Security Insights 2.0 file https://github.com/ossf/security-insights
2+
# Specification: https://github.com/ossf/security-insights/tree/main/spec
3+
34
header:
45
schema-version: 2.0.0
5-
last-updated: '2025-07-26'
6-
last-reviewed: '2025-07-26'
6+
last-updated: '2025-09-18'
7+
last-reviewed: '2025-09-18'
78
url: https://github.com/openfga/openfga.dev
89
project-si-source: https://raw.githubusercontent.com/openfga/.github/main/SECURITY-INSIGHTS.yml
910
comment: OpenFGA website and documentation.
@@ -16,31 +17,31 @@ repository:
1617
accepts-automated-change-request: true
1718
no-third-party-packages: false
1819
core-team:
19-
- name: Andres Aguiar
20-
affiliation: Okta
21-
22-
social: https://github.com/aaguiarz
23-
primary: true
24-
- name: Daniel Yeam
25-
affiliation: Okta
26-
27-
social: https://github.com/dyeam0
28-
- name: Patrick Dillon
29-
affiliation: Okta
30-
31-
social: https://github.com/pdillon
32-
- name: Rishav Mishra
33-
affiliation: Okta
34-
35-
social: https://github.com/rishavmishra-okta
36-
- name: Talent Zeng
37-
affiliation: Okta
38-
39-
social: https://github.com/ttrzeng
40-
- name: Tyler Nix
41-
affiliation: Okta
42-
43-
social: https://github.com/tylernix
20+
- name: Andres Aguiar
21+
affiliation: Okta
22+
23+
social: https://github.com/aaguiarz
24+
primary: true
25+
- name: Daniel Yeam
26+
affiliation: Okta
27+
28+
social: https://github.com/dyeam0
29+
- name: Patrick Dillon
30+
affiliation: Okta
31+
32+
social: https://github.com/pdillon
33+
- name: Rishav Mishra
34+
affiliation: Okta
35+
36+
social: https://github.com/rishavmishra-okta
37+
- name: Talent Zeng
38+
affiliation: Okta
39+
40+
social: https://github.com/ttrzeng
41+
- name: Tyler Nix
42+
affiliation: Okta
43+
44+
social: https://github.com/tylernix
4445

4546
license:
4647
url: https://raw.githubusercontent.com/openfga/openfga.dev/main/LICENSE
@@ -58,7 +59,7 @@ repository:
5859
self:
5960
evidence: https://github.com/cncf/tag-security/blob/main/community/assessments/projects/openfga/joint-assessment.md
6061
date: '2024-12-19'
61-
comment: OpenFGA has completed a CNCF security joint assessment with CNCF TAG Security and Compliance
62+
comment: OpenFGA has completed a CNCF security joint assessment with CNCF TAG-Security
6263

6364
tools:
6465
- name: Dependabot
@@ -70,7 +71,7 @@ repository:
7071
adhoc: false
7172
ci: true
7273
release: true
73-
comment: Dependabot is enabled for this repo to automatically update dependencies.
74+
comment: Dependabot is enabled for this repository to automatically update dependencies.
7475
- name: Snyk
7576
type: SCA
7677
version: latest
@@ -80,14 +81,24 @@ repository:
8081
adhoc: false
8182
ci: true
8283
release: true
83-
comment: Snyk is enabled for this repo to scan for vulnerabilities.
84+
comment: Snyk is enabled for this repository to scan for vulnerabilities.
8485
- name: Socket
85-
type: other
86+
type: SCA
87+
version: latest
88+
rulesets:
89+
- built-in
90+
integration:
91+
adhoc: false
92+
ci: true
93+
release: true
94+
comment: Socket is enabled for this repository to scan for supply chain security vulnerabilities.
95+
- name: OSSF Scorecard
96+
type: SCA
8697
version: latest
8798
rulesets:
8899
- built-in
89100
integration:
90101
adhoc: false
91102
ci: true
92103
release: true
93-
comment: Socket is enabled for this repo to scan for supply chain security vulnerabilities.
104+
comment: OSSF Scorecard is enabled for this repository.

blog/fine-grained-news-2025-01.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -68,7 +68,7 @@ We are very grateful with the OpenFGA community, who helped shipping **126** rel
6868

6969
[Andres Aguiar](https://www.linkedin.com/in/aaguiar/) from Okta was invited to present on the Maintainer’s Summit at KubeCon Europe aaout our experiences collaborating with the CNCF TAG-Security team: [A Project Maintainers Guide To TAG Security](https://maintainersummiteu2025.sched.com/event/1tj8v/a-project-maintainers-guide-to-tag-security-marina-moore-edera-andres-aguiar-okta).
7070

71-
[Mark Laing](https://www.linkedin.com/in/mark-laing/) from Canonical will present at FOSDEM about [Fine-grained access control in LXD with OpenFGA](https://fosdem.org/2025/schedule/event/fosdem-2025-6194-fine-grained-access-control-in-lxd-with-openfga/).
71+
[Mark Laing](https://www.linkedin.com/in/mark-laing/) from Canonical will present at FOSDEM about [Fine-grained access control in LXD with OpenFGA](https://archive.fosdem.org/2025/schedule/event/fosdem-2025-6194-fine-grained-access-control-in-lxd-with-openfga/).
7272

7373
## **See You Next Month:**
7474

0 commit comments

Comments
 (0)