ietf-scitt / use-cases

SCITT Use Cases
Creative Commons Zero v1.0 Universal
4 stars 6 forks source link

Use Case: Attestations of alignment to S2C2F and org overlays #18

Open pdxjohnny opened 1 year ago

pdxjohnny commented 1 year ago

This is very much a work in progress, largely unstarted, just posting here to consolidate notes first transparently

WIP DRAFT: https://github.com/pdxjohnny/use-cases/blob/openssf_metrics/openssf_metrics.md

Related: https://github.com/ietf-scitt/use-cases/issues/14 Related: https://github.com/ossf/s2c2f/blob/main/specification/framework.md#appendix-relation-to-scitt Related: https://github.com/intel/dffml/pull/1454

This use case will be mostly focused on the policy / gatekeeper component and federation components of SCITT.

This use case is a specialization of (cross between) the following use cases from the Detailed Software Supply Chain Uses Cases for SCITT doc.



2022-07-20 OpenSSF Identifying Security Threats WG Meeting Notes