Tip
Reporting a vulnerability? Please do not open an issue in this repository. Report it privately to the affected OpenTelemetry repository, following that repo's security policy. See the security response guidelines for how reports are handled.
OpenTelemetry provides vendor-agnostic telemetry instrumentations and collection components which can be used by a wide variety of libraries, services and apps. Being one of the most popular CNCF projects, many vendors and customers use OpenTelemetry to observe their software systems. That reach means the security of OpenTelemetry matters to a lot of people.
That's why we created this SIG (Special Interest Group) - to focus on the process and procedures for security across the OpenTelemetry project, and to work with the community so security work is transparent, shared, and well supported.
We would love your help! As OpenTelemetry adoption grows, so does the volume of security work, and automated and AI-assisted scanning has added both more findings and more complexity to triaging them. We do this work in the open - our process, our findings, and how we respond in public. If you have experience in supply chain security, or would simply like to learn, please say hi in CNCF Slack.
For details, see CONTRIBUTING.md. Some of what the SIG maintains, and good places to start reading:
- Security response guidelines - how vulnerabilities are handled and disclosed across the project
- Security dashboard - OpenSSF Scorecard status for every OpenTelemetry repository
- Recommendations and architecture decision records - the guidance and decisions the SIG has published
The SIG meets every other Monday at 09:00 PT. Agenda and meeting notes are in the Google doc. Anyone is welcome to join, and questions that need more discussion than Slack can carry are a good fit for the agenda.
Refer to the OpenTelemetry Community document on how to use Slack and the shared community calendar.
- Reiley Yang, Microsoft
For more information about the maintainer role, see the community repository.
- Adriel Perkins, Liatrio
- Trask Stalnaker, Microsoft
For more information about the approver role, see the community repository.
For more information about the emeritus role, see the community repository.