Skip to content

Add CNCF governance files for Sandbox application#137

Open
Jovonni wants to merge 4 commits into
masterfrom
cncf/governance-files
Open

Add CNCF governance files for Sandbox application#137
Jovonni wants to merge 4 commits into
masterfrom
cncf/governance-files

Conversation

@Jovonni
Copy link
Copy Markdown
Collaborator

@Jovonni Jovonni commented May 14, 2026

Summary

Adds all 7 required governance files for the CNCF Sandbox application:

  • ROADMAP.md — 4-phase roadmap (Production Hardening → Ecosystem → Scale → Incubation)
  • CONTRIBUTING.md — Contribution guide with DCO requirement
  • CODE_OF_CONDUCT.md — Contributor Covenant v2.1
  • MAINTAINERS.md — Active maintainer listing
  • SECURITY.md — Vulnerability reporting policy with response SLAs
  • GOVERNANCE.md — Project governance model
  • ADOPTERS.md — Known users/deployments

Remaining blocker: GPL → Apache 2.0 relicense (#1).

Jovonni added 4 commits May 14, 2026 14:34
…INTAINERS, SECURITY, GOVERNANCE, ADOPTERS

Prepares OpenUBA for CNCF Sandbox application by adding all required
governance documentation per CNCF project lifecycle requirements.

- ROADMAP.md: 4-phase roadmap from production hardening to incubation readiness
- CONTRIBUTING.md: Contribution guide with DCO requirement
- CODE_OF_CONDUCT.md: Contributor Covenant v2.1
- MAINTAINERS.md: Active maintainer listing
- SECURITY.md: Vulnerability reporting policy with response timeline
- GOVERNANCE.md: Project governance model (roles, decision-making, maintainer path)
- ADOPTERS.md: Known users/deployments listing

Resolves blockers #2-7 from CNCF application (OSSVCs#76).
Remaining blocker: GPL → Apache 2.0 relicense (#1).
Updates SECURITY.md and CODE_OF_CONDUCT.md to use the official
GACWR organization email instead of personal email.
CRDs (UBATraining, UBAInference, UBAPipeline, UBAWorkspace), Kopf
operator, multi-backend model registry (GitHub, HuggingFace, Kubeflow,
OpenUBA Hub adapters), model scheduler, PostGraphile/GraphQL, hash
verification, and workspace notebooks all already exist in the codebase.

Moved these from roadmap Phase 1 to Current State section. Remaining
roadmap items are truly unbuilt: Helm chart, HPA, multi-tenancy,
CNCF integrations (Falco, OTel, OPA), and community features.
Visual Rule Builder (ReactFlow drag-and-drop, 664 LOC) and LLM
Investigation Assistant (omnipresent chat window, 559 LOC, multi-provider)
both already exist in the codebase. Moved from Phase 3 roadmap to
Current State section.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant