Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Software Supply Chain Best Practices v2 #1216

Open
8 of 19 tasks
mnm678 opened this issue Jan 18, 2024 · 9 comments
Open
8 of 19 tasks

Software Supply Chain Best Practices v2 #1216

mnm678 opened this issue Jan 18, 2024 · 9 comments
Assignees

Comments

@mnm678
Copy link
Collaborator

mnm678 commented Jan 18, 2024

Description: what's your idea?

Impact: Describe the customer impact of the problem. Who will this help? How
will it help them?

Scope: How much effort will this take? ok to provide a range of options if or
"not yet determined" for initial proposals. Feel free to include proposed tasks
below or link a Google doc

Intent to lead:

  • I volunteer to be a project lead on this proposal if the community is
    interested in pursing this work.
    This statement of intent does not preclude
    others from co-leading or becoming lead in my stead.

Proposal to Project:

  • Added to the planned meeting template for 01 24
  • Raised in a Security TAG meeting to determine interest - mm dd
  • Collaborators comment on issue for determine interest and nominate project
    lead
  • Scope determined via meeting mm dd and/or shared document add link
    with call for participation in #tag-security slack channel thread add link
    and mailing list email add link
  • Scope presented to Security TAG leadership and Sponsor is assigned

TO DO

@mnm678 mnm678 added proposal common precursor to project, for discussion & scoping triage-required Requires triage supplychain labels Jan 18, 2024
@mnm678 mnm678 self-assigned this Jan 18, 2024
@jkjell
Copy link
Collaborator

jkjell commented Jan 19, 2024

Count me in! ☺️

@developer-guy
Copy link
Contributor

we (w/@Dentrax) would love to help!

@Vombato
Copy link
Contributor

Vombato commented Jan 19, 2024

I would love to help too 🤚🏻

@mnm678
Copy link
Collaborator Author

mnm678 commented Jan 31, 2024

We will be kicking off this effort in the working group meeting tomorrow! (Thursday at 11am US eastern time)

@mnm678 mnm678 added in-progress and removed proposal common precursor to project, for discussion & scoping triage-required Requires triage labels Feb 6, 2024
@mnm678 mnm678 moved this to 🏗 In progress in Supply Chain Working Group Feb 12, 2024
@PushkarJ PushkarJ changed the title [Proposal] Software Supply Chain Best Practices v2 Software Supply Chain Best Practices v2 Apr 24, 2024
@PushkarJ PushkarJ added the project work of the group label Apr 24, 2024
@PushkarJ PushkarJ added this to the STAG Rep: @mnm678 milestone Apr 24, 2024
@mnm678
Copy link
Collaborator Author

mnm678 commented Aug 22, 2024

The paper is ready for community review! We'd appreciate any feedback: https://docs.google.com/document/d/1IQ6tVdxfXX-y5oOjRWUspIrK5xDmVbJ8-XieCG5Cgko/edit#heading=h.otreoolht20w.

@ai2017
Copy link
Contributor

ai2017 commented Aug 28, 2024

Is there a deadline to submit the review comments ?

@mnm678
Copy link
Collaborator Author

mnm678 commented Aug 29, 2024

We're hoping to have all comments by next Thursday (September 5)

@georgalis
Copy link

FYI - I've added many comments to the Software Supply Chain Best Practices v2 doc today, and just completed extensive review in slack. https://cloud-native.slack.com/archives/C01KL0B4LKC/p1725490453437489 I think the slack items are in scope, but there are so many that they may need deferral for next rev? Please reply to threads to calibrate scope! Thanks.

@eddie-knight
Copy link
Collaborator

The markdown for this whitepaper was merged in #1396

Next step is for @mnm678 to work with CNCF to produce a PDF

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Status: wrapping up
Status: 👀 In review
Development

No branches or pull requests

8 participants