The S2C2F Project is a group working within the OpenSSF's Supply Chain Integrity Working Group formed to further develop and continuously improve the S2C2F guide which outlines and defines how to securely consume Open Source Software (OSS) dependencies into the developer’s workflow.
Other
179
stars
24
forks
source link
Create Supplemental Material for deeper dives and clarification #24
Definition of Supplemental Material: A 1-2 page write up to provide clarification on certain scenarios.
Example list of initial Supplemental Guides: