finos / devops-automation

Provide a continuous compliance and assurance approach to DevOps that mutually benefits banks, auditors and regulators whilst accelerating DevOps adoption in engineering and fintech IT departments.
http://devops.finos.org
Apache License 2.0
56 stars 17 forks source link

Software Security Supply Chain - Working Group Meeting - Thursday 20 Jun 2023 #105

Open mcleo-d opened 1 year ago

mcleo-d commented 1 year ago

Date

Thursday 20 Jun 2023 - 09:00 EST / 14:00 UK

Untracked attendees

Name Firm Comment

Meeting notices

Agenda

Decisions Made

Action Items

Zoom info

Join Zoom Meeting

Github Repo: https://github.com/finos/devops-automation/

Project Board: https://github.com/orgs/finos/projects/33

Mailing List: Email devops-mutualization+subscribe@finos.org to subscribe to our mailing list

robmoffat commented 1 year ago

Rob / FINOS 👟

psmulovics commented 1 year ago

Peter Smulovics / Morgan Stanley 🏦

mcleo-d commented 1 year ago

James McLeod / FINOS

Iletee commented 1 year ago

Ilkka Turunen / Sonatype

johnmark commented 1 year ago

JM Walker / Fannie Mae

ashukla13 commented 1 year ago

Amol Shukla / Morgan Stanley

josspo commented 1 year ago

Joss Poupeney / FINOS

maoo commented 1 year ago

Maurizio Pillitu / FINOS

brunon commented 1 year ago

Bruno Navert / Morgan Stanley

adrianbele commented 1 year ago

Adrian Bele / Red Hat

brooklynrob commented 1 year ago

Rob Underwood / JPMC

jonmuk commented 1 year ago

Jon Meadows (Citi)

brunon commented 1 year ago

Challenge: lack of visibility. Applications have hundreds of OSS software components, where are the real issues, how do we identify and surface them to focus on the important things?

rhyddian commented 1 year ago

Rhyddian Olds @ Citi

johnmark commented 1 year ago

Rob U: top 1000 open source projects used in FS? We have limited resources - are we willing to contribute actual resources to this? Will we commit to using output?

johnmark commented 1 year ago

Jonathan Meadows: can we use the output of the FSI threat intelligence group fsisac.com - 50K banks - connected to openssf

rhyddian commented 1 year ago

Jonathan Meadows: can we use the output of the FSI threat intelligence group fsisac.com - 50K banks - connected to openssf

* what is the work product? Created top 100 list of open source libraries

Financial Services Information Sharing and Analysis Center (FS-ISAC)

johnmark commented 1 year ago

Rob U: between FS-ISAC and this group - do we need to exist? James: can we still pull learning from other groups into larger devops automation group? Rhyddian: if there are gaps, let's examine the gaps Rob M: are there introductory docs we can point people to

johnmark commented 1 year ago

Decision: for orgs that haven't signed a CLA, they can open/amend issues, which project leads then convert into cards on the project board

Boundaries (James) - are we focusing on internal processes, proprietary or non-proprietary products?

robmoffat commented 1 year ago

I am interested in building a view on what the state of the art looks like - these are the docs we want for osr.finos.org. If that helps drive out an understanding of the gaps, then that's great. Happy to work on these docs with the group.

nitinNayar commented 1 year ago

nitin semgrep

robmoffat commented 1 year ago

Regarding threat models: I think this is something we could review as a group.

Is there a definitively maintained list anywhere?

Also useful:

brunon commented 1 year ago

Gaps to discuss: lack of common industry-standard solutions to address software end-of-life in financial services