Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Software Bill of Materials and provenance artifacts #575

Open
janosdebugs opened this issue Oct 9, 2023 · 0 comments
Open

Software Bill of Materials and provenance artifacts #575

janosdebugs opened this issue Oct 9, 2023 · 0 comments
Labels
Cloud Native Security Slam 2023 https://github.com/orgs/ContainerSSH/discussions/574 feature New feature or request help wanted Extra attention is needed

Comments

@janosdebugs
Copy link
Contributor

janosdebugs commented Oct 9, 2023

Abstract

A software bill of materials presents users of ContainerSSH with a comprehensive list of all parts that ContainerSSH is made of. Provenance artifacts describe the entire history of code in ContainerSSH itself.

Background

The Cloud Native Security Slam is an event helping big consumers of ContainerSSH, such as Epic Games and the US Space Force consume ContainerSSH in a more secure manner.

Implementing it in ContainerSSH

ContainerSSH already has a license checker which compiles the NOTICE file shipped with all releases. This would need to be changed into a tool that exports a machine-readable SBOM format.

Further reading

@janosdebugs janosdebugs added feature New feature or request help wanted Extra attention is needed Cloud Native Security Slam 2023 https://github.com/orgs/ContainerSSH/discussions/574 labels Oct 9, 2023
@janosdebugs janosdebugs changed the title Software Bill of Materials (Cloud Native Security Slam) Software Bill of Materials Oct 9, 2023
@janosdebugs janosdebugs changed the title Software Bill of Materials Software Bill of Materials and provenance artifacts Oct 9, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Cloud Native Security Slam 2023 https://github.com/orgs/ContainerSSH/discussions/574 feature New feature or request help wanted Extra attention is needed
Projects
None yet
Development

No branches or pull requests

1 participant