IBM / bamoe

Code for IBM Business Automation Manager Open Editions (BAMOE)
https://www.ibm.com/products/business-automation-manager-open-editions
Apache License 2.0
8 stars 17 forks source link

Software supply chain security #66

Open mroussel opened 2 months ago

mroussel commented 2 months ago

We are evaluating the migration from RHPAM to IBM BAMOE. Due to security concerns, we want to evaluate the supply chain of the container images found on quay.io. This repository seems to have some elements missing:

It is possible to retrospectively inspect the images from quay.io, but we don’t think that is the way to go in an open-source project. Red Hat explains everything here: Red Hat Software Supply Chain Security.

Thanks for your help.