1
- # Security Insights 2.0 file https://github.com/ossf/security-insights
2
- # Schema: https://github.com/ossf/security-insights/blob/main/spec/schema.cue
3
1
header :
4
2
schema-version : 2.0.0
5
3
last-updated : ' 2025-07-26'
@@ -16,31 +14,31 @@ repository:
16
14
accepts-automated-change-request : true
17
15
no-third-party-packages : false
18
16
core-team :
19
- - name : Andres Aguiar
20
- affiliation : Okta
21
-
22
- social : https://github.com/aaguiarz
23
- primary : true
24
- - name : Daniel Yeam
25
- affiliation : Okta
26
-
27
- social : https://github.com/dyeam0
28
- - name : Patrick Dillon
29
- affiliation : Okta
30
-
31
- social : https://github.com/pdillon
32
- - name : Rishav Mishra
33
- affiliation : Okta
34
-
35
- social : https://github.com/rishavmishra-okta
36
- - name : Talent Zeng
37
- affiliation : Okta
38
-
39
- social : https://github.com/ttrzeng
40
- - name : Tyler Nix
41
- affiliation : Okta
42
-
43
- social : https://github.com/tylernix
17
+ - name : Andres Aguiar
18
+ affiliation : Okta
19
+
20
+ social : https://github.com/aaguiarz
21
+ primary : true
22
+ - name : Daniel Yeam
23
+ affiliation : Okta
24
+
25
+ social : https://github.com/dyeam0
26
+ - name : Patrick Dillon
27
+ affiliation : Okta
28
+
29
+ social : https://github.com/pdillon
30
+ - name : Rishav Mishra
31
+ affiliation : Okta
32
+
33
+ social : https://github.com/rishavmishra-okta
34
+ - name : Talent Zeng
35
+ affiliation : Okta
36
+
37
+ social : https://github.com/ttrzeng
38
+ - name : Tyler Nix
39
+ affiliation : Okta
40
+
41
+ social : https://github.com/tylernix
44
42
45
43
license :
46
44
url : https://raw.githubusercontent.com/openfga/openfga.dev/main/LICENSE
@@ -51,14 +49,14 @@ repository:
51
49
dependency-management-policy : https://github.com/openfga/openfga/blob/main/docs/dependencies-policy.md
52
50
governance : https://github.com/openfga/.github/blob/main/GOVERNANCE.md
53
51
review-policy : https://github.com/openfga/.github/blob/main/CONTRIBUTING.md
54
- security-policy : https://github.com/openfga/openfga.dev/security .md
52
+ security-policy : https://github.com/openfga/openfga.dev/SECURITY .md
55
53
56
54
security :
57
55
assessments :
58
56
self :
59
57
evidence : https://github.com/cncf/tag-security/blob/main/community/assessments/projects/openfga/joint-assessment.md
60
58
date : ' 2024-12-19'
61
- comment : OpenFGA has completed a CNCF security joint assessment with CNCF TAG Security and Compliance
59
+ comment : OpenFGA has completed a CNCF security join assessment with CNCF TAG- Security
62
60
63
61
tools :
64
62
- name : Dependabot
@@ -70,7 +68,7 @@ repository:
70
68
adhoc : false
71
69
ci : true
72
70
release : true
73
- comment : Dependabot is enabled for this repo to automatically update dependencies.
71
+ comment : Dependabot is enabled for this repository to automatically update dependencies.
74
72
- name : Snyk
75
73
type : SCA
76
74
version : latest
@@ -80,14 +78,4 @@ repository:
80
78
adhoc : false
81
79
ci : true
82
80
release : true
83
- comment : Snyk is enabled for this repo to scan for vulnerabilities.
84
- - name : Socket
85
- type : other
86
- version : latest
87
- rulesets :
88
- - built-in
89
- integration :
90
- adhoc : false
91
- ci : true
92
- release : true
93
- comment : Socket is enabled for this repo to scan for supply chain security vulnerabilities.
81
+ comment : Snyk is enabled for this repository to scan for vulnerabilities.
0 commit comments