Security SIG Update
Kay Williams <kayw@...>
Hi All,
I won’t be able to make the TOC meeting today, but I wanted to provide an update from the Security SIG.
The main focus right now is an effort to create an industry standard for a ‘Software Bill of Materials’. You can learn more at the project web page:
https://www.it-cisq.org/software-bill-of-materials/
We are tracking to submit a draft specification on November 11.
If you, or someone you know, would like to get involved in this effort, please send me an email.
Kay
|
|
Re: FYI: New LF Telemetry Policy
Kohsuke Kawaguchi
I think it's reasonable to assume that what we already do is grandfathered in, but it'd be good to have Jenkins go through this review process to meet the new bar.
On Mon, Oct 21, 2019 at 9:23 PM Oleg Nenashev <o.v.nenashev@...> wrote:
--
Kohsuke Kawaguchi
|
|
Re: FYI: New LF Telemetry Policy
Oleg Nenashev
Hi all, Does this policy apply to telemetry engines which were introduced *before* the new policy was announced? It is not clear from the text, but it is important if it becomes a policy for CDF projects. Thanks in advance, Oleg Nenashev Jenkins project
On Tue, Oct 22, 2019, 01:57 Dan Lopez <dlopez@...> wrote:
|
|
Re: FYI: New LF Telemetry Policy
Dan Lopez <dlopez@...>
Thanks, Dan! It is also on the agenda for tomorrow TOC call. Best,
On Mon, Oct 21, 2019 at 4:38 PM Dan Lorenc via Lists.Cd.Foundation <dlorenc=google.com@...> wrote:
|
|
FYI: New LF Telemetry Policy
Dan Lorenc <dlorenc@...>
This was recently published: https://www.linuxfoundation.org/telemetry-data-policy/ It covers the policies and review process for the collection of data. We might want to consider adding this to our project guidelines. Dan Lorenc
|
|
Re: [cdf-outreach] Is the Landscape ready for prime time?
Dan Lopez <dlopez@...>
This has been fixed.
On Tue, Oct 8, 2019 at 2:25 PM Tara Hernandez via Lists.Cd.Foundation <tarahernandez=google.com@...> wrote:
|
|
Re: [cdf-outreach] Is the Landscape ready for prime time?
One more niggly PR filed to fix some language in the README for that repo: https://github.com/cdfoundation/cdf-landscape/pull/37
On Fri, Oct 4, 2019 at 12:15 PM Chris Aniszczyk <caniszczyk@...> wrote:
--
Tara Hernandez Engineering Manager Google Cloud
|
|
Re: [cdf-outreach] Is the Landscape ready for prime time?
Moritz Plassnig
I like the approach of using the "core focus area". How would you objectively define that (to avoid vendors arguing forever about it)?
On Mon, Oct 7, 2019 at 12:15 PM TracyRagan <tracy@...> wrote:
--
|
|
Re: Regrets tomorrow
Sure thing, enjoy Tokyo!
On Sun, Oct 6, 2019 at 11:25 PM Kohsuke Kawaguchi <kk@...> wrote:
--
Tara Hernandez Engineering Manager Google Cloud
|
|
Regrets tomorrow
Kohsuke Kawaguchi
I'm traveling in Tokyo and therefore I won't be able to make it to the TOC meeting tomorrow. I'm hoping Tara would be able to run the meeting for us. Kohsuke Kawaguchi
|
|
Re: How are other projects signing releases?
Kohsuke Kawaguchi
I've added my thought as a comment to the PR.
On Thu, Oct 3, 2019 at 6:03 PM Olivier Vernin <olivier@...> wrote:
--
Kohsuke Kawaguchi
|
|
Re: Proposal: MLOps Sig
Animesh Singh
Thanks all. There is great interest in this working group, and so far we have seen Github, Cloud Bees, Google onboard apart from IBM. I will now formally put in the right repo - and figure out a biweekly cadence which can work out for all of us, and get it kickstarted.
Please leave your email id on the github issue or the doc if you would like to participate.
|
|
Re: Is the Landscape ready for prime time?
Michael Neale
I had 2 PRs open which were moving some things around I thought were important. There is another PR open for a new project I saw - would be good to address those if possible.
On Sat, 5 Oct 2019 at 4:42 am, Tracy Ragan <tracy@...> wrote:
--
Regards, Michael Neale twitter: @michaelneale, skype: michael_d_neale Cell: +61 423175597 (Australia) Cofounder @ CloudBees
|
|
Re: [cdf-outreach] Is the Landscape ready for prime time?
Ravi Lachhman
Thanks Tara!
On Fri, Oct 4, 2019 at 4:01 PM Tara Hernandez via Lists.Cd.Foundation <tarahernandez=google.com@...> wrote:
|
|
Re: [cdf-outreach] Is the Landscape ready for prime time?
Hi Ravi, the CDF has its own version of that posted here: https://github.com/cdfoundation/toc/blob/master/PROJECT_LIFECYCLE.md
On Fri, Oct 4, 2019 at 12:36 PM Ravi Lachhman <ravi.lachhman@...> wrote:
--
Tara Hernandez Engineering Manager Google Cloud
|
|
Re: [cdf-outreach] Is the Landscape ready for prime time?
Balaji Siva
Hi Tracy, logo placements seems little off. Can I call you for a quick discussion? I would think it would make sense to have the primary project on the top and vendors on the bottom row for the CI and Pipeline box. Thanks Balaji 408 201 2124
|
|
Re: [cdf-outreach] Is the Landscape ready for prime time?
Ravi Lachhman
Just out of curiosity, what is the criteria for "graduation"? Following the CNCF criteria?
On Fri, Oct 4, 2019 at 3:15 PM Chris Aniszczyk <caniszczyk@...> wrote:
|
|
Re: [cdf-outreach] Is the Landscape ready for prime time?
Issue Tracking SGTM Also here is the link for folks who don't have it readily available:
On Fri, Oct 4, 2019 at 1:42 PM TracyRagan <tracy@...> wrote:
--
Chris Aniszczyk (@cra) | +1-512-961-6719
|
|
Re: Announcing the CDF Security SIG
Kay Williams <kayw@...>
Correction. SIG-Security meetings will be held at 8 AM Pacific. Our first meeting will be next Tuesday 10/8. Join us!
From: Kay Williams
Sent: Friday, October 4, 2019 10:26 AM To: cdf-toc@... <cdf-toc@...>; sig-security@... <sig-security@...> Subject: Announcing the CDF Security SIG Hey everyone, I am excited to announce the formation of the Security SIG - the CD Foundation’s first Special Interest Group (SIG)! The Security SIG began as a lightning talk at the first CD Summit in Barcelona this past May, and progressed to a formal proposal in August. In September it was adopted by the Technical Operating Committee (TOC). The charter for the Security SIG is to provide a neutral home for discussion around designs, specifications, code and processes to enable security across the software supply chain. Topics of interest include the following:
Membership in the Security SIG is open to the public. Here are some details: Communication
Meetings
All are welcome to join the mailing list and attend meetings. We look forward to building a more secure future together! Sincerely, Kay
|
|
Announcing the CDF Security SIG
Kay Williams <kayw@...>
Hey everyone, I am excited to announce the formation of the Security SIG - the CD Foundation’s first Special Interest Group (SIG)! The Security SIG began as a lightning talk at the first CD Summit in Barcelona this past May, and progressed to a formal proposal in August. In September it was adopted by the Technical Operating Committee (TOC). The charter for the Security SIG is to provide a neutral home for discussion around designs, specifications, code and processes to enable security across the software supply chain. Topics of interest include the following:
Membership in the Security SIG is open to the public. Here are some details: Communication
Meetings
All are welcome to join the mailing list and attend meetings. We look forward to building a more secure future together! Sincerely, Kay
|
|