You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Governmental bodies that use or audit software are increasingly asking OSS projects to prove integrity of software artifacts and to document artifact provenance.
Software bills of materials (SBOMs) and initiatives such as SLSA.dev can help in these areas
While CFF processes genrate some of this SBOM information and can guarantee integrity of some artifacts, these processes are not consistent across CFF artifacts and not complete.
Paketo and kpack already generate SBOMs and annotate them on the images they build.
The TOC and the Working Groups should decide how far we would like the projects to go in supporting these emerging supply-chain standards, which standards to implement, and then assign responsibility to one or more bodies within the CFF to carry out the work.
The text was updated successfully, but these errors were encountered:
@pburkholder raised this as a discussion topic during the 2022-05-10 TOC meeting. Capturing some of the discussion context here:
The TOC and the Working Groups should decide how far we would like the projects to go in supporting these emerging supply-chain standards, which standards to implement, and then assign responsibility to one or more bodies within the CFF to carry out the work.
The text was updated successfully, but these errors were encountered: