cloudfoundry / community

Governance and contact information for Cloud Foundry
Apache License 2.0
39 stars 174 forks source link

Identify and implement CFF-wide standards to support supply-chain risk management #373

Open emalm opened 2 years ago

emalm commented 2 years ago

@pburkholder raised this as a discussion topic during the 2022-05-10 TOC meeting. Capturing some of the discussion context here:

The TOC and the Working Groups should decide how far we would like the projects to go in supporting these emerging supply-chain standards, which standards to implement, and then assign responsibility to one or more bodies within the CFF to carry out the work.

pburkholder commented 2 years ago

Thanks for the succinct issue description, @emalm

rkoster commented 1 year ago

The first step for incorporating supply chain related files in bosh releases is currently being discussed here: https://github.com/cloudfoundry/bosh/discussions/2466

beyhan commented 1 year ago

This is still revenant and the TOC plans to look into this.