-
Notifications
You must be signed in to change notification settings - Fork 229
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Workstream: Dependency Track #961
Comments
Since dependencies does overlap, i just want folks to remember the original thread on source that @marcelamelara and I originally were thinking through #463 Also, dependencies and some of source can also leverage s2c2f controls and maybe SLSA can just require/reference those controls "integrate/handshake" with S2C2F. @camaleon2016 and i have discussed this in the past and have talked about it from an SCI WG gap assessment. |
There are many different aspects to dependencies which will be relevant to hardening the supply chain. Instead of creating a track just for dependencies, it might make more sense to figure out how dependencies relate across various other current, proposed, or in development tracks. As an example, another related property to dependencies is reproducibility (i.e. in terms of ensuring that dependencies are appropriately pins as a basic requirement towards achieving reproducibility). I mentioned this relationship in the document which has been started for the reproducibility (#873 (comment)). The initial proposal for reproducibility was to tack it on to the build track, but my proposal was to instead include it as higher ordered levels on top of these basic dependency-based properties. |
Hi everyone, I'd like to start drawing some boundaries around what the Dependencies Track will cover:
Given the breadth of risks, both in nature and impact, the track likely doesn't need to get too specific about things like known vulnerabilities and SLOs, etc and instead focus on improvements and controls that enable effective management of that risk. Would love to hear others' thoughts and comments and if that aligns with their thinking. |
@meder Underneath the OpenSSF we also have a framework called S2C2F - https://github.com/ossf/s2c2f that is focused on secure consumption of open source software. I wonder if we can reference stuff from here as part of a dependency track. S2C2F has mostly been focused on end user ingestion of upstream dependencies, but I can see us working to create a loop here where following some set of S2C2F practices along with maybe a few other SLSA specific things would create that loop where:
@adriandiglio Thoughts? @ |
+1 This is an excellent way to get all the benefits of both SLSA and S2C2F. I've been pushing this from the start. |
@mlieberman85 @camaleon2016, thanks, let's keep that in mind while discussing the implementation. As the starting point I'm sharing the draft Google Doc where we can have a more concrete and targeted discussion: |
We discussed a dependency track in the community meeting on Aug 28, 2023. It may have significant overlap with the Source Track, so we should discuss them together.
The text was updated successfully, but these errors were encountered: