Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

proposal: merge 14.2.4 and 14.2.5 and move to V1.14 #2165

Open
elarlang opened this issue Oct 20, 2024 · 0 comments
Open

proposal: merge 14.2.4 and 14.2.5 and move to V1.14 #2165

elarlang opened this issue Oct 20, 2024 · 0 comments
Labels
1) Discussion ongoing Issue is opened and assigned but no clear proposal yet 4) proposal for review Issue contains clear proposal for add/change something next meeting Filter for leaders V1 V14

Comments

@elarlang
Copy link
Collaborator

elarlang commented Oct 20, 2024

Spin-off from #2088

Current requirement:

# Description L1 L2 L3 CWE
14.2.4 Verify that third party components come from pre-defined, trusted and continually maintained repositories. 829
14.2.5 Verify that a Software Bill of Materials (SBOM) is maintained of all third party libraries in use.

Some comments to keep ind mind:

V14.2.4 is something you need to define, check from repositories and document. So this requirement does not belong to V14.2 but is more current V1.14 material as a "documentation requirement".

V14.2.5 is documentation requirement as well, although it can be handled technically.

In #2088 (comment) I recommended.

From that "getting stuck into the SBOM declaration", I would say, that SBOM is just one, but not the only, option to handle inventory of 3rd party libraries in use and I propose to turn back to the requirement version we had in v4.0.2

V14.2.5 Verify that an inventory catalog is maintained of all third party libraries in use.

My proposal:

# Description L1 L2 L3 CWE
1.14.? [MODIFIED, MOVED FROM 14.2.5, MERGED FROM 14.2.4] Verify that an inventory catalog, such as software bill of materials (SBOM), is maintained of all third-party libraries in use, including verifying that components come from pre-defined, trusted, and continually maintained repositories.
@elarlang elarlang added V14 V1 1) Discussion ongoing Issue is opened and assigned but no clear proposal yet 4) proposal for review Issue contains clear proposal for add/change something labels Oct 20, 2024
@elarlang elarlang added the next meeting Filter for leaders label Oct 21, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
1) Discussion ongoing Issue is opened and assigned but no clear proposal yet 4) proposal for review Issue contains clear proposal for add/change something next meeting Filter for leaders V1 V14
Projects
None yet
Development

No branches or pull requests

1 participant