ossf / s2c2f

The S2C2F Project is a group working within the OpenSSF's Supply Chain Integrity Working Group formed to further develop and continuously improve the S2C2F guide which outlines and defines how to securely consume Open Source Software (OSS) dependencies into the developer’s workflow.
Other
167 stars 23 forks source link

Review marked-up review from Melba Lopez #22

Open david-a-wheeler opened 1 year ago

david-a-wheeler commented 1 year ago

On 2023-06-06 Melba Lopez walked through a number of comments on the S2C2 document. See the WG meeting notes for the discussion we had then. We need to walk through the rest of the comments & then decide what to do about them. I'll be attaching the PDF she shared via Slack.

david-a-wheeler commented 1 year ago

Here is the PDF document with Melba's comments: Secure_Supply_Chain_ConsumptionFramework(S2C2F).pdf

jasminewang0 commented 1 year ago

PR #25 addresses the following:

The following issues are outstanding: