Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add 2024 Q4 Sigstore Update #413

Merged
merged 1 commit into from
Dec 5, 2024
Merged

Add 2024 Q4 Sigstore Update #413

merged 1 commit into from
Dec 5, 2024

Conversation

haydentherapper
Copy link
Contributor

Closes #412

Closes ossf#412

Signed-off-by: Hayden B <[email protected]>
@haydentherapper haydentherapper requested a review from a team as a code owner November 22, 2024 17:27
Copy link
Member

@steiza steiza left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks!

@marcelamelara marcelamelara added the TI Update Quarterly TI update. Needs 5 approvals, 7d review. label Nov 25, 2024
Copy link
Contributor

@mlieberman85 mlieberman85 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@haydentherapper
Copy link
Contributor Author

Thanks all, can someone merge?

Copy link
Contributor

@marcelamelara marcelamelara left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great update, thanks @haydentherapper !

@marcelamelara
Copy link
Contributor

Thanks all, can someone merge?

These types of PRs need 5 approvals, I'll ping folks on Slack.

Copy link
Contributor

@lehors lehors left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sigstore has all the signs of a successful, well run project which should inspire other OpenSSF projects!

Although I think it should, our report template doesn't currently prompt for this but I'd appreciate any info on how Sigstore is doing with the implementation of the Security Baseline. What's the status? Are there any issues encountered?

Thanks.


### Conference

Our second [SigstoreCon: Supply Chain Day](https://events.linuxfoundation.org/sigstorecon-supply-chain-day/) conference just wrapped up. With just over 90 attendees, SigstoreCon brought together individuals and organizations excited about not only Sigstore but other supply chain initiatives such as SLSA, SBOM, or in-toto. Talks are recorded [here](https://www.youtube.com/playlist?list=PLM6mY5TOhY1E02_fQWqfQk_gMRHHtX0q6).
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Using “here” as a link anchor is an anti-pattern.
For more info see the following blog post (from a renowned expert. ;-) : https://lehors.wordpress.com/2009/01/29/linking-the-proper-way/

@lehors
Copy link
Contributor

lehors commented Dec 3, 2024

Thanks all, can someone merge?

These types of PRs need 5 approvals, I'll ping folks on Slack.

I actually think that TI reports should get reviewed by as many TAC members as possible. There is no rush and in my opinion it's more important that everybody gets a chance to be informed.

@bobcallaway bobcallaway requested a review from a team December 4, 2024 00:04
@bobcallaway
Copy link
Contributor

Although I think it should, our report template doesn't currently prompt for this but I'd appreciate any info on how Sigstore is doing with the implementation of the Security Baseline. What's the status? Are there any issues encountered?

As part of the TI graduation process earlier in 2024, the Sigstore TSC documented status against the best practices badge requirements - which I know isn't exactly the same as the security baseline, but is probably the closest we have to documenting the overall posture of the Sigstore project.

Copy link
Contributor

@sevansdell sevansdell left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great work Sigstore!

I'm also personally interested in the ability to sign model cards, with an effort in the AIML WG, Model Signing SIG.

@steiza steiza merged commit 920e02f into ossf:main Dec 5, 2024
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
TI Update Quarterly TI update. Needs 5 approvals, 7d review.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Sigstore Project Update - Nov 2024
7 participants