Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
101 changes: 51 additions & 50 deletions .github/SECURITY-INSIGHTS.yml
Original file line number Diff line number Diff line change
@@ -1,9 +1,10 @@
# Security Insights 2.0 file https://github.com/ossf/security-insights
# Schema: https://github.com/ossf/security-insights/blob/main/spec/schema.cue
# Security Insights 2.0 file https://github.com/ossf/security-insights
# Specification: https://github.com/ossf/security-insights/tree/main/spec

header:
schema-version: 2.0.0
last-updated: '2025-07-26'
last-reviewed: '2025-07-26'
last-updated: '2025-09-18'
last-reviewed: '2025-09-18'
url: https://github.com/openfga/api
project-si-source: https://raw.githubusercontent.com/openfga/.github/main/SECURITY-INSIGHTS.yml
comment: Protocol Buffers used by OpenFGA.
Expand All @@ -16,47 +17,47 @@ repository:
accepts-automated-change-request: true
no-third-party-packages: false
core-team:
- name: Poovamraj Thanganadar Thiagarajan
affiliation: Okta
email: [email protected]
social: https://github.com/poovamraj
primary: true
- name: Adrian Tam
affiliation: Okta
email: [email protected]
social: https://github.com/adriantam
- name: Jose Padilla
affiliation: Okta
email: [email protected]
social: https://github.com/jpadilla
- name: Joshua Jones
affiliation: Okta
email: [email protected]
social: https://github.com/senojj
- name: Justin Cohen
affiliation: Okta
email: [email protected]
social: https://github.com/justincoh
- name: Raghd Hamzeh
affiliation: Okta
email: [email protected]
social: https://github.com/rhamzeh
- name: Victoria Johns
affiliation: Okta
email: [email protected]
social: https://github.com/vic-dev
- name: Will Vedder
affiliation: Okta
email: [email protected]
social: https://github.com/willvedd
- name: Yamil Asusta
affiliation: Okta
email: [email protected]
social: https://github.com/elbuo8
- name: Zilvinas Vilutis
affiliation: Okta
email: [email protected]
social: https://github.com/cikasfm
- name: Poovamraj Thanganadar Thiagarajan
affiliation: Okta
email: [email protected]
social: https://github.com/poovamraj
primary: true
- name: Adrian Tam
affiliation: Okta
email: [email protected]
social: https://github.com/adriantam
- name: Jose Padilla
affiliation: Okta
email: [email protected]
social: https://github.com/jpadilla
- name: Joshua Jones
affiliation: Okta
email: [email protected]
social: https://github.com/senojj
- name: Justin Cohen
affiliation: Okta
email: [email protected]
social: https://github.com/justincoh
- name: Raghd Hamzeh
affiliation: Okta
email: [email protected]
social: https://github.com/rhamzeh
- name: Victoria Johns
affiliation: Okta
email: [email protected]
social: https://github.com/vic-dev
- name: Will Vedder
affiliation: Okta
email: [email protected]
social: https://github.com/willvedd
- name: Yamil Asusta
affiliation: Okta
email: [email protected]
social: https://github.com/elbuo8
- name: Zilvinas Vilutis
affiliation: Okta
email: [email protected]
social: https://github.com/cikasfm

license:
url: https://raw.githubusercontent.com/openfga/api/main/LICENSE
Expand All @@ -67,14 +68,14 @@ repository:
dependency-management-policy: https://github.com/openfga/openfga/blob/main/docs/dependencies-policy.md
governance: https://github.com/openfga/.github/blob/main/GOVERNANCE.md
review-policy: https://github.com/openfga/.github/blob/main/CONTRIBUTING.md
security-policy: https://github.com/openfga/api/security.md
security-policy: https://github.com/openfga/api/SECURITY.md

security:
assessments:
self:
evidence: https://github.com/cncf/tag-security/blob/main/community/assessments/projects/openfga/joint-assessment.md
date: '2024-12-19'
comment: OpenFGA has completed a CNCF security joint assessment with CNCF TAG Security and Compliance
comment: OpenFGA has completed a CNCF security joint assessment with CNCF TAG-Security

champions:
- name: Justin Cohen
Expand All @@ -90,7 +91,7 @@ repository:
adhoc: false
ci: true
release: true
comment: Dependabot is enabled for this repo to automatically update dependencies.
comment: Dependabot is enabled for this repository to automatically update dependencies.
- name: Snyk
type: SCA
version: latest
Expand All @@ -100,9 +101,9 @@ repository:
adhoc: false
ci: true
release: true
comment: Snyk is enabled for this repo to scan for vulnerabilities.
comment: Snyk is enabled for this repository to scan for vulnerabilities.
- name: Socket
type: other
type: SCA
version: latest
rulesets:
- built-in
Expand Down
Loading