OWASP / DevSecOpsGuideline

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.
https://owasp.org/www-project-devsecops-guideline/
Other
848 stars 198 forks source link

Software Composition Analysis & Supply Chain Risk Management #48

Open mostafa opened 2 years ago

mostafa commented 2 years ago

Hey!

I see that the SCA is a little bit less developed than other parts of the doc, so I'd be happy to expand on this to include various techniques, technologies, tools, and workflows on how this is done in a real-world scenario. Let me know if that's what you're interested in. I also gave a talk about it here.

Ali-Yazdani commented 2 years ago

Hi @mostafa, Sounds good. Please feel free and start your contribution to this domain. I'm looking forward to approving your Pull Request. :D

fdicarlo commented 2 years ago

Hi,

On supply chain could be nice also to add Sigstore, happy to contribute on it as well :)