Skip to content

[Initiative]: Security Slam - Autumn / Winter 2026 #2279

Description

@zigmax

Name

Security Slam - Autumn / Winter 2026

Short description

Continue and evolve the CNCF Security Slam as a recurring initiative to help CNCF projects identify, prioritize, and implement meaningful security improvements, with a proposed in-person component at the CNCF Maintainer Summit complemented by longer-form remote collaboration.

Responsible group

TAG Security and Compliance

Does the initiative belong to a subproject?

No

Subproject name

No response

Primary contact

@zigmax

Additional contacts

@jkjell

Initiative description

The CNCF Security Slam is a community initiative that brings together CNCF project maintainers, contributors, and security practitioners to identify and implement concrete security improvements across CNCF projects.

Previous editions have demonstrated the value of this approach.

The 2025 Security Slam experimented with targeted in-person collaboration at KubeCon + CloudNativeCon Europe. Participating projects produced concrete outcomes, including security-focused pull requests, CI/CD security improvements, and renewed project-level security efforts.

An important lesson from the 2025 edition was that the preparation work between maintainers and TAG Security was particularly valuable, while the 45-minute collaboration format was too constrained for deeper hands-on work.

The Spring 2026 Security Slam evolved the model into a month-long initiative, with a strong focus on helping projects adopt and improve against the OpenSSF Open Source Project Security Baseline (OSPS Baseline). The initiative combined documentation, tooling, automation, security advisors, and direct collaboration with maintainers.

The Spring 2026 Transparency Report highlighted measurable improvements across participating projects and identified several opportunities for future iterations, including starting project outreach earlier, increasing automation, and engaging more directly with incubating CNCF projects.

Building on these lessons, we propose continuing the Security Slam as a recurring TAG Security and Compliance initiative with a hybrid model combining the CNCF Maintainer Summit with longer-form community collaboration.

The initiative would focus on:

  • engaging CNCF projects ahead of each Security Slam;
  • helping maintainers assess their current security posture;
  • identifying and prioritizing actionable security improvements;
  • creating well-defined security backlogs for contributors;
  • leveraging frameworks such as the OSPS Baseline to provide measurable objectives;
  • using automation and tooling where possible to reduce participation friction;
  • connecting maintainers with security practitioners and contributors;
  • using the Maintainer Summit as an opportunity for focused, in-person collaboration; and
  • continuing the work through a longer-form remote Security Slam.

Maintainer Summit integration

We propose using the CNCF Maintainer Summit as a key part of the next iteration of the Security Slam.

The Maintainer Summit already brings together maintainers from across the CNCF ecosystem and provides a strong opportunity to engage projects directly around security.

A Security Slam activity at the Maintainer Summit could be used to:

  • introduce the Security Slam to a broader group of CNCF maintainers;
  • engage projects that may not otherwise participate in a dedicated security initiative;
  • review project security posture with maintainers;
  • identify and prioritize security gaps;
  • build actionable security backlogs;
  • connect maintainers directly with TAG Security and Compliance members and other security practitioners;
  • run targeted hands-on security working sessions; and
  • prepare projects for continued collaboration after the Summit.

Rather than attempting to complete all security work during the event itself, the Maintainer Summit would serve as an entry point and acceleration phase for the broader Security Slam.

Projects could use the Summit to identify security priorities, meet security contributors, and define concrete work items. Those activities could then continue during the longer-form remote phase of the Security Slam.

This model directly addresses lessons from previous editions: in-person collaboration is valuable for establishing relationships, identifying opportunities, and creating momentum, while meaningful implementation often requires more time than a short conference session can provide.

The Maintainer Summit is therefore an important proposed component of the initiative, but the broader Security Slam would not be contingent on acceptance of a Maintainer Summit session or activity. If an in-person component cannot be accommodated, the remote Security Slam can still proceed.

Proposed model

We propose structuring the initiative around three phases:

  1. Preparation

Ahead of the Maintainer Summit:

  • identify interested CNCF projects;
  • engage maintainers early;
  • review existing security posture and relevant OSPS Baseline requirements;
  • identify initial improvement opportunities; and
  • prepare tooling, documentation, and contributor guidance.
  1. Maintainer Summit

During the Maintainer Summit:

  • host focused Security Slam working sessions;
  • work directly with maintainers to validate security priorities;
  • identify actionable issues and backlog items;
  • connect projects with security practitioners and contributors; and
  • establish clear next steps for each participating project.
  1. Extended Security Slam

Following the Summit:

  • continue collaboration remotely over a longer period;
  • support contributors working on identified security issues;
  • provide security guidance and review where needed;
  • track improvements and merged contributions; and
  • document outcomes and lessons learned.

This would combine the strengths of both previous models: the direct engagement and relationship-building of the in-person format with the deeper collaboration enabled by the month-long Security Slam.

Deliverable(s) or exit criteria

Expected deliverables and measurable outcomes may include:

  • participating CNCF projects identified and onboarded;
  • a Security Slam activity organized at the CNCF Maintainer Summit, if accepted;
  • security posture reviews performed with participating maintainers;
  • actionable security backlogs created;
  • security-related issues and pull requests opened and/or merged;
  • measurable improvements against the OSPS Baseline or other relevant CNCF security guidance;
  • participating projects connected with security contributors and practitioners;
  • continued collaboration following the Maintainer Summit;
  • lessons learned and recommendations documented; and publication of a Transparency Report following the initiative.

The broader goal is to establish the Security Slam as a repeatable mechanism that uses both in-person maintainer engagement and longer-form community collaboration to translate CNCF security guidance into concrete improvements across CNCF projects.

Tracking document for meeting and progress

https://notes.cncf.io/s/ABJacxc19

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions