Meshery Security Self-Assessment refreshed

33 views
Skip to first unread message

Mia Grenell

unread,
Jun 10, 2026, 6:15:52 PM (12 days ago) Jun 10
to Meshery Maintainers, Meshery Developers
Hi Everyone,

A few Meshery maintainers spent time refreshing the project's security self-assessment this week. 


Please review and remark at your leisure.

Best,
Mia

Mohd Hamza

unread,
Jun 10, 2026, 6:25:47 PM (12 days ago) Jun 10
to Meshery Developers, mia.gre...@gmail.com, Meshery Maintainers
Hi Mia, All,

I spent time reviewing today and offered a couple of comments in the document. One comment that I think is worth repeating here and being heard a bit more broadly is that of any ongoing reference to service mesh technology. I think most everyone here understands that the genesis of the project was in part in context of that specific technology, however, the project broke free of that constrained association some time ago (i.e. . I think the continued association with this technology (even simply the mention of it) does the project and all of our hard work a disservice. In my mind, when people become aware of the project, as they give it a cursory look, and if they stumble upon those two words, service and mesh, they quickly conclude that the project is only useful if they are using those technologies; those two words only serve to reinforce the individual's internal feeling that the "mesh" portion of Meshery's name was in reference to service mesh technology. 

What I am saying is that I think to the extent we can simply not mention that technology, all the better. I know I've heard some of the other maintainers and Calcote say this a handful of times, so I assume that there's I understand that there's no disagreement in here, however, it doesn't hurt to reinforce that the absence of the words is probably the best choice in most cases, including in the security self-assessment. Or at least that's my opinion.

Regards,
Mohd.
----
TCS Labs

Lee Calcote

unread,
Jun 10, 2026, 11:14:23 PM (12 days ago) Jun 10
to Meshery Developers, mohd....@tata-consulting.co.uk, mia.gre...@gmail.com, Meshery Maintainers
List of known security vulnerabilities has been updated - https://docs.meshery.io/project/security-vulnerabilities/
Reply all
Reply to author
Forward
0 new messages