kubernetes / release

Release infrastructure for Kubernetes and related components
Apache License 2.0
485 stars 504 forks source link

SLSA3 Missing pieces #2616

Open puerco opened 2 years ago

puerco commented 2 years ago

This issue is meant to track the remaining work needed to push towards SLSA3 in our release process. This initial dump is meant to dump the remaining tasks before we prioritize them. Please note that pushing towards SLSA level 3 means effectively complying with level 2, thus all L2 tasks are folded into this list.

These remaining items are based on our SLSA Compliance Assessment tracking sheet.

Remaining SLSA Level 3 Compliance Tasks:

Provenance - Service Generated

Build as Code

Provenance - Non-falsifiable

Identify Entry Point

Related Efforts:

Ensure Integrity of Our Builder!

File Signing

Sign & Promote SBOMs

*Note: tasks prefixed with Builder: are part of an upcoming provenance builder proposal (not ready yet)

ameukam commented 2 years ago

Infra: Plan signer account and access

I think it's https://github.com/kubernetes/k8s.io/pull/3854

puerco commented 2 years ago

@ameukam sorry the one liner may be a bit misleading. I think this point needs a little more clarification so I've opened https://github.com/kubernetes/release/issues/2617 to expand the idea and discuss!

saschagrunert commented 2 years ago

I guess everything except #2618 belongs to the SLSA KEP: https://github.com/kubernetes/enhancements/tree/master/keps/sig-release/3027-slsa-compliance

Do we have to update it?

k8s-triage-robot commented 2 years ago

The Kubernetes project currently lacks enough contributors to adequately respond to all issues and PRs.

This bot triages issues and PRs according to the following rules:

You can:

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle stale

saschagrunert commented 2 years ago

/remove-lifecycle stale

k8s-triage-robot commented 1 year ago

The Kubernetes project currently lacks enough contributors to adequately respond to all issues.

This bot triages un-triaged issues according to the following rules:

You can:

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle stale

k8s-triage-robot commented 1 year ago

The Kubernetes project currently lacks enough active contributors to adequately respond to all issues.

This bot triages un-triaged issues according to the following rules:

You can:

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle rotten

cpanato commented 1 year ago

/remove-lifecycle rotten

k8s-triage-robot commented 10 months ago

The Kubernetes project currently lacks enough contributors to adequately respond to all issues.

This bot triages un-triaged issues according to the following rules:

You can:

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle stale

xmudrii commented 10 months ago

/remove-lifecycle stale

k8s-triage-robot commented 7 months ago

The Kubernetes project currently lacks enough contributors to adequately respond to all issues.

This bot triages un-triaged issues according to the following rules:

You can:

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle stale

xmudrii commented 7 months ago

/lifecycle frozen