Dosu LogoDosu Logo
Ask
Join our Discord
Organization avatar
CNCFPublic
CNCF's Dosu Org
DocumentsCNCF
Which CNCF projects are currently seeking security contributions, and where can I find more information about their focus areas?
Which CNCF projects are currently seeking security contributions, and where can I find more information about their focus areas?
Type
Answer
Status
Published
Created
Oct 18, 2025
Updated
Oct 18, 2025
Created by
Dosu Bot
Updated by
Dosu Bot

Here is a markdown table summarizing CNCF projects actively seeking security contributions, including their focus areas and links for more information:

ProjectDescription / Focus AreaMaturity LevelWebsiteContribution / Security Info
NATSSecure messaging system; needs maintainers and security help for governance and license protectionGraduatednats.ioCNCF call for support
FluxGitOps for Kubernetes; focused on multi-tenant workload identity and secure deliveryGraduatedfluxcd.ioSecurity contributions
KubescapeKubernetes security and compliance; growing project seeking contributors for security featuresIncubatingkubescape.ioIncubation announcement
BomctlSBOM tooling for supply chain security; open to security-focused contributionsSandbox/EcosystemGitHubSupply chain security guide
GUACGraph for Understanding Artifact Composition (SBOM analysis); supply chain securitySandbox/EcosystemGitHubSupply chain security guide
in-totoSupply chain integrity framework; open to security contributionsIncubatingin-toto.ioSupply chain security guide
ProtobomSBOM interoperability; supply chain securitySandbox/EcosystemGitHubSupply chain security guide
SBOMitSBOM generation and management; supply chain securitySandbox/EcosystemGitHubSupply chain security guide
SLSASecure software supply chain frameworkSandbox/Ecosystemslsa.devSupply chain security guide
TUFSecure software update frameworkGraduatedtheupdateframework.ioSupply chain security guide
FalcoRuntime threat detection for containers and KubernetesIncubatingfalco.orgFalco GitHub
OPAPolicy as code for cloud native environmentsGraduatedopenpolicyagent.orgOPA GitHub
KyvernoKubernetes policy engineIncubatingkyverno.ioKyverno GitHub
TAG SecurityCNCF Security Technical Advisory Group; join working groups, contribute to guides and assessmentsAdvisory GroupTAG SecurityHow to get involved

You’ll find good-first-issues and help-wanted tags in these repositories to get started. For broader impact, consider joining CNCF TAG Security working groups or contributing to supply chain security projects.

For training resources on CNCF security projects, check out Linux Foundation Training for courses like Kubernetes Security Specialist (CKS), Secure Software Supply Chain, and more.

Documents
Ask CNCF
Ask CNCF - Start Here!
CNCF Security Contributions
How do I become a CNCF Ambassador?
What CNCF working groups are there?
Events
Deadlines and CFPs
KubeCon + CloudNativeCon EU 2026 Attendee Guide
KubeCon + CloudNativeCon NA 2025 Attendee Guide
Example Questions
CNCF Security Contributions
How are the CNCF Technical Oversight Committee (TOC), End User Technical Advisory Board (TAB), TAGs, and related groups organized, and what are their roles and relationships as of 2025?
How do I become a CNCF Ambassador?
What CNCF working groups are there?
What mentorship programs does the CNCF offer and how can someone participate?
When and where is the next Cloud Native Rejekts event, and in which other cities has Rejekts been hosted?
Where can I find the schedule for upcoming CNCF events and meetings?
Which CNCF projects are currently seeking security contributions, and where can I find more information about their focus areas?
Which KubeCon parties feature BBQ?
Who are the current members of the CNCF Technical Oversight Committee (TOC) as of October 2025?
KubeCon EU 2026
Day 0 - Monday
Day 1 - Tuesday
Day 2 - Wednesday
Day 3 - Thursday
KubeCon + CloudNativeCon EU 2026 Attendee Guide
KubeCon NA 2025
Day 0 - Monday
Day 1 - Tuesday
Day 2 - Wednesday
Day 3 - Thursday
KubeCon + CloudNativeCon NA 2025 Attendee Guide
Projects
CNCF Project Birthdays
Reference Architectures
Adobe's Reference Architecture
Allianz Direct's Reference Architecture
Sponsors
VAST Data
Training
Training Opportunities
How can someone with experience in Go, Kubernetes, cloud-native security, and eBPF/XDP networking start contributing to CNCF security projects, particularly KubeArmor, and which channels, SIGs, or maintainers should they connect with?
What is a structured learning plan for someone with Linux, networking, and security experience to become CNCF ready?
slack-workspace-migration.md