Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Working Group #15

Open
gbaz opened this issue Nov 9, 2021 · 1 comment
Open

Security Working Group #15

gbaz opened this issue Nov 9, 2021 · 1 comment

Comments

@gbaz
Copy link
Collaborator

gbaz commented Nov 9, 2021

A note to be fleshed out into a proposal -- the github advisory database team is looking for collaboration opportunities here, and the rust secure code wg may have some things to offer in inspiration (https://github.com/rust-secure-code/wg)

Some basic components: a database (perhaps bootstrapping off the github database), a way to publish and verify CVEs, and integrated hackage/cabal querying to warn about bad deps, perhaps auto-hooked to the solver.

Also: a trusted team and point of contact (ghc already now has one). Not sure what the other components of "good" ecosystem-wide security practices are, but this is a start, and more suggestions are welcome.

@gbaz
Copy link
Collaborator Author

gbaz commented Mar 30, 2022

arguably a correct first step is just cloning the basic ideas here https://github.com/rustsec/advisory-db

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant