cdfoundation / sig-interoperability

CDF Interoperability SIG
Apache License 2.0
64 stars 40 forks source link

Add Software Supply Chain Stages to Pipeline Stage Terminology #97

Closed fdegir closed 1 year ago

fdegir commented 2 years ago

CDF SIG Software Supply Chain started working on identifying pipeline stages that may be employed by organizations to ensure the security and compliance of the software they are consuming and producing.

This commit is the first commit in series, adding the first pipeline stage, OSS Introduction Stage, in order to seek community feedback.

More information about this stage is available on SIG Software Supply Chain PoC document: https://hackmd.io/U6q685gFTdWRrkWZechvGw?view#OSS-Introduction

fdegir commented 2 years ago

Cc'in some of the SIG Software Supply Chain folks who may have missed this PR since it was sent on the existing documentation in this repository: @lmilbaum @gkunz @mgreau @majinghe @todaywasawesome @davidmirror-ops @tdcox

Some notes from the discussion during SIG Software Supply Chain Meeting on 2022-04-28:

@tdcox tried to write the points you highlighted down based on the notes I've taken during the meeting. Please update if I missed and/or misquoted things.

justinabrahms commented 1 year ago

Please feel free to open this if you would still like this change, but given it's staleness, I think folks have moved on.