Added CNCF required project documents. #2328
No reviewers
Labels
No labels
1week
2weeks
Failed compliance check
IP cameras
NATS
Possible security concern
Review effort 1/5
Review effort 2/5
Review effort 3/5
Review effort 4/5
Review effort 5/5
UI
aardvark
accessibility
amd64
api
arm64
auth
back-end
bgp
blog
bug
build
checkers
ci-cd
cleanup
cnpg
codex
core
dependencies
device-management
documentation
duplicate
dusk
ebpf
enhancement
eta 1d
eta 1hr
eta 3d
eta 3hr
feature
fieldsurvey
github_actions
go
good first issue
help wanted
invalid
javascript
k8s
log-collector
mapper
mtr
needs-triage
netflow
network-sweep
observability
oracle
otel
plug-in
proton
python
question
reddit
redhat
research
rperf
rperf-checker
rust
sdk
security
serviceradar-agent
serviceradar-agent-gateway
serviceradar-web
serviceradar-web-ng
siem
snmp
sysmon
topology
ubiquiti
wasm
wontfix
zen-engine
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
carverauto/serviceradar!2328
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "refs/pull/2328/head"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Imported from GitHub pull request.
Original GitHub pull request: #1785
Original author: @marvin-hansen
Original URL: https://github.com/carverauto/serviceradar/pull/1785
Original created: 2025-10-16T10:14:42Z
Original updated: 2025-10-16T14:03:27Z
Original head: main
Original base: main
Original merged: 2025-10-16T14:03:27Z by @mfreeman451
User description
Added the remaining files to comply with CNCF project standards:
PR Type
Documentation
Description
Added CNCF compliance documentation including governance, maintainers, security contacts, and telemetry policy
Created governance framework with decision-making process, release procedures, and maintainer guidelines
Documented telemetry data collection policy with opt-out instructions
Added CNCF pre-application checklist tracking compliance requirements
Diagram Walkthrough
File Walkthrough
GOVERNANCE.md
Define project governance and decision-making frameworkGOVERNANCE.md
responsibilities
Actions
MAINTAINERS.md
Document project maintainers listMAINTAINERS.md
@mfreeman451and@marvin-hansenROADMAP.md
Add empty project roadmap placeholderROADMAP.md
SECURITY_CONTACTS.md
Establish security contact and reporting processSECURITY_CONTACTS.md
TELEMETRY.md
Define telemetry collection policy and opt-out mechanismTELEMETRY.md
usage, performance metrics
configuration
CNCF_Pre_check.md
Add CNCF pre-application compliance checklistdocs/LF/CNCF_Pre_check.md
Imported GitHub PR comment.
Original author: @qodo-code-review[bot]
Original URL: https://github.com/carverauto/serviceradar/pull/1785#issuecomment-3410168699
Original created: 2025-10-16T10:15:20Z
You are nearing your monthly Qodo Merge usage quota. For more information, please visit here.
PR Compliance Guide 🔍
Below is a summary of compliance checks for this PR:
Incomplete disclosure policy
Description: The security contacts file contains placeholder links ('$LINK' and HTML TODO) instead of
an actual embargo policy URL and coordinated vulnerability disclosure/reporting
instructions, which may cause researchers to disclose issues improperly.
SECURITY_CONTACTS.md [7-11]
Referred Code
🎫 No ticket provided
Codebase context is not defined
Follow the guide to enable codebase context checks.
No custom compliance provided
Follow the guide to enable custom compliance check.
Compliance status legend
🟢 - Fully Compliant🟡 - Partial Compliant
🔴 - Not Compliant
⚪ - Requires Further Human Verification
🏷️ - Compliance label
Imported GitHub PR comment.
Original author: @qodo-code-review[bot]
Original URL: https://github.com/carverauto/serviceradar/pull/1785#issuecomment-3410172479
Original created: 2025-10-16T10:16:31Z
You are nearing your monthly Qodo Merge usage quota. For more information, please visit here.
PR Code Suggestions ✨
Explore these optional code suggestions:
Address critical gaps and inconsistencies in documentation
Fix the incomplete security reporting instructions in
SECURITY_CONTACTS.md.Also, resolve inconsistencies across the new documentation, such as duplicated
maintainer lists, incorrect communication channel names, and varying GitHub
repository URLs.
Examples:
SECURITY_CONTACTS.md [10-11]
GOVERNANCE.md [13-17]
Solution Walkthrough:
Before:
Resolve the
$LINKandTODOplaceholders inSECURITY_CONTACTS.md. Replace themwith the actual links to the embargo policy and the security vulnerability
reporting instructions.
SECURITY_CONTACTS.md [7-11]
[Suggestion processed]Suggestion importance[1-10]: 9
__
Why: The suggestion correctly identifies critical missing information in the security process documentation, as the placeholders for the embargo policy and vulnerability reporting instructions are unresolved.
✅
Fix incorrect GitHub repository linkSuggestion Impact:
The commit changes the repository URL in TELEMETRY.md exactly as suggested, correcting it to github.com/carverauto/serviceradar.code diff:
Correct the GitHub repository link in
TELEMETRY.mdtogithub.com/carverauto/serviceradarto be consistent with other documents in thePR.
TELEMETRY.md [48]
[Suggestion processed]Suggestion importance[1-10]: 6
__
Why: The suggestion correctly identifies an inconsistent and incorrect GitHub repository URL, and fixing it is important for ensuring users are directed to the correct project page.
✅
Correctly label the community platformSuggestion Impact:
The commit updated the label and link text from "Community Slack" to "Community Discord" exactly as suggested.code diff:
In
GOVERNANCE.md, change the text "Community Slack" to "Community Discord" tomatch the provided Discord invite link.
GOVERNANCE.md [53]
[Suggestion processed]Suggestion importance[1-10]: 5
__
Why: The suggestion correctly points out that the link text "Community Slack" is misleading as the URL points to a Discord server, and fixing it improves user experience and document accuracy.
Imported GitHub PR review comment.
Original author: @qodo-code-review[bot]
Original URL: https://github.com/carverauto/serviceradar/pull/1785#discussion_r2435459426
Original created: 2025-10-16T10:54:47Z
Original path: SECURITY_CONTACTS.md
Original line: 11
Suggestion: Resolve placeholders for security links
Imported GitHub PR review comment.
Original author: @qodo-code-review[bot]
Original URL: https://github.com/carverauto/serviceradar/pull/1785#discussion_r2435460249
Original created: 2025-10-16T10:55:03Z
Original path: TELEMETRY.md
Original line: 48
Suggestion: Fix incorrect GitHub repository link
Imported GitHub PR review comment.
Original author: @qodo-code-review[bot]
Original URL: https://github.com/carverauto/serviceradar/pull/1785#discussion_r2435463372
Original created: 2025-10-16T10:56:06Z
Original path: GOVERNANCE.md
Original line: 53
Suggestion: Correctly label the community platform