Skip to content
This repository has been archived by the owner on Nov 14, 2023. It is now read-only.

Use Case: Attestations of alignment to S2C2F and org overlays #14

Open
pdxjohnny opened this issue Sep 7, 2022 · 0 comments
Open

Use Case: Attestations of alignment to S2C2F and org overlays #14

pdxjohnny opened this issue Sep 7, 2022 · 0 comments

Comments

@pdxjohnny
Copy link

pdxjohnny commented Sep 7, 2022

This issue is to track the creation of a use case example which also serves as the plan between members of the OpenSSF, IETF, DFFML, and other communities as they work on said use case.

Collection of metric data into shared database (crowdsourcable OpenSSF Metrics).
There are many repos to search, we want to enable self reporting and granularity
as applicable to ad-hoc formed policy as desired by end-user. We want this to
work across fully decentrailized, federated, and central forges/factories.

  • Related: https://github.com/ossf/s2c2f/blob/main/specification/framework.md#appendix-relation-to-scitt
  • This use case will be mostly focused on the policy / gatekeeper component and federation components of SCITT.
    • 5.2.2: Registration Policies
    • 7: Federation
  • This use case is a specialization of (cross between) the following use cases from the Detailed Software Supply Chain Uses Cases for SCITT doc.
    • 3.3: Security Analysis of a Software Product
      • We'll cover OpenSSF Scorecard and other analysis mechanisms including meta static analysis / aggregation (example: GUAC).
    • 3.4: Promotion of a Software Component by multiple entities
      • We'll cover how these entities can leverage analysis mechanisms to achieve feature and bugfix equilibrium across the diverged environment.
        • Future use cases could explore semantic patching to patch across functionally similar

Info can later be checked when others downstream build models based on the crowdsourced scraped data.

WIP DRAFT: https://github.com/pdxjohnny/use-cases/blob/openssf_metrics/openssf_metrics.md

References:

pdxjohnny added a commit to pdxjohnny/use-cases that referenced this issue Sep 27, 2022
pdxjohnny added a commit to intel/dffml that referenced this issue Mar 24, 2023
…ire: Update link to OpenSSF Metrics IETF SCITT use case to RFCv4.1

Related: ietf-scitt/use-cases#14
pdxjohnny added a commit to intel/dffml that referenced this issue Mar 30, 2023
…ocker-compose: Add scitt API emulator

Related: scitt-community/scitt-api-emulator#25
Related: ietf-scitt/use-cases#14
Related: https://codeberg.org/forgejo/discussions/issues/12
Related: ietf-scitt/use-cases#18
Signed-off-by: John Andersen <johnandersenpdx@gmail.com>
pdxjohnny added a commit to intel/dffml that referenced this issue Mar 30, 2023
@pdxjohnny pdxjohnny changed the title OpenSSF Metrics Use Case: Attestations of alignment to S2C2F and org specific overlays Apr 1, 2023
@pdxjohnny pdxjohnny changed the title Use Case: Attestations of alignment to S2C2F and org specific overlays Use Case: Attestations of alignment to S2C2F and Org Overlays Apr 1, 2023
@pdxjohnny pdxjohnny changed the title Use Case: Attestations of alignment to S2C2F and Org Overlays Use Case: Attestations of alignment to S2C2F and org overlays Apr 1, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant