erlef / security-wg

Repo for the Security Working Group
https://erlef.github.io/security-wg/
192 stars 17 forks source link

Supply Chain Security #1

Open max-au opened 4 years ago

max-au commented 4 years ago

Ensure supply chain security for code/package repositories (e.g. hex.pm)

voltone commented 2 years ago

Let's collect some thoughts here, we can discuss in the next meeting how we want to turn this into actionable tasks/projects/documents. I would suggest we try to answer the following questions:

voltone commented 2 years ago

What kind of supply chain security issues are we trying to protect against?

Some possibilities:

DianaOlympos commented 2 years ago

Following the Biden Admin EO, we can expect a lot of talks about SBOM.

Worth pointing out for people to have a look at are GITBOM Analysis of the supply chain landscape by the OSFF