ossf / wg-securing-software-repos

OpenSSF Working Group on Securing Software Repositories
Other
84 stars 15 forks source link

Produce cryptographic signing guide for package managers #10

Open znewman01 opened 1 year ago

znewman01 commented 1 year ago

Lots of ink has been spilled on cryptographic signing in package managers (see "Misc. references" below). And we've certainly had our fair share of discussion in this working group. Still, new package managers pop up every day and must rehash many of these conversations for themselves (not to mention existing package managers that want to add security features after-the-fact).

Subtleties involve:

This group is in a good position to produce some documentation (I've even written some about this though it's not in a digestible format) that covers:

I don't think we want to be too prescriptive, but we can help focus some of these discussions and make sure folks have all the relevant context when making decisions, plus even give step-by-step adoption guidelines.

Please feel free to add other references, other open questions, and (best) volunteer to coordinate this!

Misc. references

(Due to personal interest, I pay most attention to the proposals that involve Sigstore, but feel free to suggest others.)

feelepxyz commented 1 year ago

@znewman01 great initiative! I would love to help out here and share any learnings from GitHub and working on provenance for npm.

steiza commented 9 months ago

We covered some, but not all, of this content in #17.

There were some requests for additional content on https://github.com/ossf/wg-securing-software-repos/pull/17#issuecomment-1627388801 that we could think about addressing in future docs.