finos / devops-automation

Provide a continuous compliance and assurance approach to DevOps that mutually benefits banks, auditors and regulators whilst accelerating DevOps adoption in engineering and fintech IT departments.
http://devops.finos.org
Apache License 2.0
61 stars 18 forks source link

Discussion Topic: Criteria used to regulate OSS libraries/modules used #113

Open ashukla13 opened 1 year ago

ashukla13 commented 1 year ago

Discussion Topic for OSS Supply Chain Risks WG

Description of Problem:

Most regulated organizations have a predefined criteria to regulate which OSS libraries/modules get onboarded and used in their applications to conform to security, compliance, and licensing requirements.

Topics to discuss

Potential Solutions:

To be discussed

johnmark commented 1 year ago

discussion point: golden repos vs or with scanning