Documents
Which CNCF projects are currently seeking security contributions, and where can I find more information about their focus areas?
Which CNCF projects are currently seeking security contributions, and where can I find more information about their focus areas?
Type
Answer
Status
Published
Created
Oct 18, 2025
Updated
Oct 18, 2025
Created by
Dosu Bot
Updated by
Dosu Bot

Here is a markdown table summarizing CNCF projects actively seeking security contributions, including their focus areas and links for more information:

ProjectDescription / Focus AreaMaturity LevelWebsiteContribution / Security Info
NATSSecure messaging system; needs maintainers and security help for governance and license protectionGraduatednats.ioCNCF call for support
FluxGitOps for Kubernetes; focused on multi-tenant workload identity and secure deliveryGraduatedfluxcd.ioSecurity contributions
KubescapeKubernetes security and compliance; growing project seeking contributors for security featuresIncubatingkubescape.ioIncubation announcement
BomctlSBOM tooling for supply chain security; open to security-focused contributionsSandbox/EcosystemGitHubSupply chain security guide
GUACGraph for Understanding Artifact Composition (SBOM analysis); supply chain securitySandbox/EcosystemGitHubSupply chain security guide
in-totoSupply chain integrity framework; open to security contributionsIncubatingin-toto.ioSupply chain security guide
ProtobomSBOM interoperability; supply chain securitySandbox/EcosystemGitHubSupply chain security guide
SBOMitSBOM generation and management; supply chain securitySandbox/EcosystemGitHubSupply chain security guide
SLSASecure software supply chain frameworkSandbox/Ecosystemslsa.devSupply chain security guide
TUFSecure software update frameworkGraduatedtheupdateframework.ioSupply chain security guide
FalcoRuntime threat detection for containers and KubernetesIncubatingfalco.orgFalco GitHub
OPAPolicy as code for cloud native environmentsGraduatedopenpolicyagent.orgOPA GitHub
KyvernoKubernetes policy engineIncubatingkyverno.ioKyverno GitHub
TAG SecurityCNCF Security Technical Advisory Group; join working groups, contribute to guides and assessmentsAdvisory GroupTAG SecurityHow to get involved

You’ll find good-first-issues and help-wanted tags in these repositories to get started. For broader impact, consider joining CNCF TAG Security working groups or contributing to supply chain security projects.

For training resources on CNCF security projects, check out Linux Foundation Training for courses like Kubernetes Security Specialist (CKS), Secure Software Supply Chain, and more.