oss-review-toolkit / ort-governance

Outline how the ORT project is governed (includes the project's charter).
Creative Commons Attribution 4.0 International
0 stars 0 forks source link

Use LFX Security Platform #13

Open tsteenbe opened 3 years ago

tsteenbe commented 3 years ago

ORT could also apply LFX Security Platform, to do so we need to provide below data:

ributors of your team who can also benefit from fund raise) -> Contributor Name + Contributor Email for each core contributor

LFX Security Platform decisions to be made by ORT TSC:

  1. Do we also want to apply LF Security Platform? (Get Snyk scans for ORT) If yes, then: A. What is our project color? B. In which category do we want to be listed? Dependency Management or ...? C. What is our elevator pitch? D. Do we want to apply for a CII badge?
sschuberth commented 3 years ago

In a video call this morning I learned from @ShubhraKar that LFX is not only about security, but also about Insights. I've enrolled ORT to get some nice statistics and visibility on the LFX platform.

Regarding security, I guess nothing speaks against signing up to that service, too. I also learned that Snyk seems to provide special conditions to LF projects in general, not just LFX, so we should check with @ShubhraKar to integrate Snyk into ORT as an advisor.

sschuberth commented 3 years ago

FYI, LFX Security on-boarding is tracked via https://jira.linuxfoundation.org/browse/LFXSEC-274. LFX Insights on-boarding is tracked via https://jira.linuxfoundation.org/plugins/servlet/theme/portal/4/SUPPORT-3923.

sschuberth commented 3 years ago

The Insights page for ORT is live: https://insights.lfx.linuxfoundation.org/projects/act%2Fort/dashboard