Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security and Compliance Category #172

Open
MarckK opened this issue Oct 20, 2021 · 6 comments
Open

Security and Compliance Category #172

MarckK opened this issue Oct 20, 2021 · 6 comments

Comments

@MarckK
Copy link
Member

MarckK commented Oct 20, 2021

###Category request:

The CDF landscape should have a security and compliance category for projects such as OPA.

@MarckK
Copy link
Member Author

MarckK commented Oct 20, 2021

@obowersa has noted the lack of a good category for tools such as white source, blackduck, etc.
#82

Note: WhiteSource is currently on the landscape un Library Management category. This may not be the best category for them.

@oleg-nenashev
Copy link
Member

I would suggest adding "Dependency management" category that IMHO includes both dependency analysis (Whitesource & Co) and update automation (e.g. Dependabot, UpdateCLI)

@MarckK
Copy link
Member Author

MarckK commented Oct 21, 2021

#175

@sbtaylor15
Copy link
Contributor

Point to the OpenSSF landscape as a embedded landscape link. This will enable us to have the OpenSSF maintain the landscape for this category.

@MarckK
Copy link
Member Author

MarckK commented Nov 12, 2021

From landscape wg meeting 12.11.21, we will keep current devsecops category on cdf landscape, as well as future linking to OpenSSF landscape.

PRs welcome to augment devsecops category

@MarckK
Copy link
Member Author

MarckK commented Nov 26, 2021

Update, with the changes to Observability and Analysis category (see #203), the DevSecOps category will appear like this:
Screenshot 2021-11-26 at 16 20 46

📣 The Security / DevSecOps category could use a good deal of augmentation.

✍️ Please add specific suggestions to this issue of additional projects / subcategories to add, etc

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants