-
Notifications
You must be signed in to change notification settings - Fork 5
Source code, CI/CD, and supply chain security #312
Copy link
Copy link
Open
Labels
blockedWaiting for an external action to occurWaiting for an external action to occurdependenciesPull requests that update a dependency filePull requests that update a dependency filedocumentationImprovements or additions to documentationImprovements or additions to documentationgithub_actionsPull requests that update GitHub Actions codePull requests that update GitHub Actions codejavaPull requests that update Java codePull requests that update Java codequestionFurther information is requestedFurther information is requested
Metadata
Metadata
Assignees
Labels
blockedWaiting for an external action to occurWaiting for an external action to occurdependenciesPull requests that update a dependency filePull requests that update a dependency filedocumentationImprovements or additions to documentationImprovements or additions to documentationgithub_actionsPull requests that update GitHub Actions codePull requests that update GitHub Actions codejavaPull requests that update Java codePull requests that update Java codequestionFurther information is requestedFurther information is requested
Type
Projects
Status
Ready
User Story
As a project maintainer, in order to have confidence in the code, how it is tested, built, and published, with it dependencies, in this repository hosting system and elsewhere, I want policy, process, and supporting automation to check security properties of the source code, the CI/CD system, and the supply chain of dependent software.
NOTE: Once maintainers (and interested community members) determine the overall policy and process approach, maintainers will integrate the relevant policy, process, and supporting automation into the other repositories. At that time, the list below will be cross-linked to relevant GitHub issues for other projects.
Goals
Dependencies
N/A
Acceptance Criteria
Revisions
No response