Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Make this repo SWSC best practices compliant #432

Open
4 tasks
marcelamelara opened this issue Apr 12, 2023 · 2 comments
Open
4 tasks

Make this repo SWSC best practices compliant #432

marcelamelara opened this issue Apr 12, 2023 · 2 comments
Assignees
Labels

Comments

@marcelamelara
Copy link
Member

marcelamelara commented Apr 12, 2023

A number of SW supply chain (SWSC) best practices frameworks have come out of CISA, NIST, and the OpenSSF. This issue tracks the implementation plan for meeting these practices.

Implementing these practices often requires multiple steps and/or tools. This issue tracks implementation progress in this issue:

  • Create SW supply chain best practices implementation doc
  • Implement NTIA minimum SBOM requirements
  • Implement OpenSSF Scorecard requirements
  • Implement OpenSSF SLSA Build L3 requirements
@marcelamelara marcelamelara changed the title Enable dependabot dependency scanner Make this repo SWSC best practices compliant Dec 12, 2023
@marcelamelara marcelamelara self-assigned this Dec 12, 2023
@prakashngit
Copy link
Contributor

Would be good to have a plan for how we intend to proceed.

@marcelamelara
Copy link
Member Author

Thanks on the ping, I have on OKR to complete a draft of a plan in Q1.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants