-
Notifications
You must be signed in to change notification settings - Fork 534
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Supply chains security Expectations vs Reality #987
Comments
Happy to contribute here. |
Happy to contribute here as well. We are currently doing this for our organisation as with capability milestones and deliverables along the secure supply chain best practices path. |
+1 |
1 similar comment
+1 |
Happy to contribute when we find a leader or organizer for this: Some examples of policies that came up during the meeting to gate/inform/gather data on:
|
+1 |
I'd be glad to try and organize efforts around this. I've worked with quite a few folks in the thread in the Supply Chain Security working group. |
I would like to contribute here. |
Signed-off-by: Brandon Lum <[email protected]>
Project Schedule
|
Signed-off-by: Brandon Lum <[email protected]> Co-authored-by: Pushkar Joglekar <[email protected]>
Hello all, On Thursday, February 16th, we're going to kick off the work for this issue during the CNCF TAG Security - Supply Chain WG meeting (11 am Eastern). The first step will be deciding on the Audience, Goals, & Broad scope. Then we will focus in on establishing the outline before distributing and working through the content sections. If you have any questions, feel free to comment on the issue, or reach out in the CNCF Slack #tag-security-supply-chain-wg channel. I hope you can join us! https://github.com/cncf/tag-security/issues/987 Also sent to TAG Security email list. |
+1 |
I would like to contribute to this topic. |
Signed-off-by: Brandon Lum <[email protected]> Co-authored-by: Pushkar Joglekar <[email protected]> Signed-off-by: Paolo Mainardi <[email protected]>
Signed-off-by: Brandon Lum <[email protected]> Co-authored-by: Pushkar Joglekar <[email protected]>
Will like to join this initiative, interesting work |
Signed-off-by: Brandon Lum <[email protected]> Co-authored-by: Pushkar Joglekar <[email protected]>
This issue has been automatically marked as inactive because it has not had recent activity. |
This is tracked by the Supply Chain WG as regular business during their bi-weekly call. For status, see the WG meeting notes. |
Signed-off-by: Brandon Lum <[email protected]> Co-authored-by: Pushkar Joglekar <[email protected]>
Description: We ask for supply chain best practices, SLSA, SBOMs, all that information.. so as to ask the question - does my software have a secure supply chain? But is that question just a pipe dream? Or can we break it down to tangible questions that we can tackle.
Impact: Being able to provide direction on what policies we want to create will help inform the data we need to produce and inform the models of attestation in the supply chain ecosystems.
Scope: Probably a month's work collecting ideas and writing them down.
Working Doc: https://docs.google.com/document/d/1_7ZDL1TtFEA4dfR3oaaVRLoWNcqthNN5h-G84y4ITkA/edit
Additional info:
The text was updated successfully, but these errors were encountered: