guac icon indicating copy to clipboard operation
guac copied to clipboard

Interested in Dev/Contributing to GUAC?

Open lumjjb opened this issue 3 years ago • 36 comments

Welcome! This thread is on expressing interest in contributing to GUAC! We are glad to welcome our fellow open source contributors! As the project is starting up, we will be creating issues that folks can pick up and work on. In the meantime, as the code base is forming up, we'd like to engage directly with our contributors!

BTW we now have a slack channel: https://openssf.slack.com/archives/C03U677QD46

If you are interested in contributing, it would be very helpful to provide the following details (copy and paste into your comment):

1. I am interested in contributing to:
- [ ] Development
- [ ] Documentation
- [ ] Issue triage and community
- [ ] Technical advisory (review [governance document](https://github.com/artifact-ff/artifact-ff/blob/main/GOVERNANCE.md#technical-advisory-members))

2. I am here because:
- [ ] Personal interest
- [ ] My company/orgs i work with are interested in this

3. What is your associated company/org if you're contributing in their capacity? _________

4. Depending on how things go, I may be interested in becoming a maintainer of the project
- [ ] Yes

5. (optional) I have expertise in:
- [ ] Neo4j
- [ ] Cypher
- [ ] GraphQL
- [ ] Intoto
- [ ] SPDX
- [ ] CycloneDX
- [ ] Others (fill in):

lumjjb avatar Aug 03 '22 19:08 lumjjb

  1. I am interested in contributing to:
  • [x] Development
  • [x] Documentation
  • [x] Issue triage and community
  • [ ] Technical advisory (review governance document)
  1. I am here because:
  • [x] Personal interest
  • [ ] My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity?

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • [x] Yes
  1. (optional) I have expertise in:
  • [ ] Neo4j
  • [ ] Cypher
  • [ ] GraphQL
  • [ ] Intoto
  • [ ] SPDX
  • [x] CycloneDX
  • [x] Others (fill in): Grype, Syft, Trivy, OSV data formats, Golang

Note: my company may be interested in the project and me contributing in their capacity, so I'll update this note if they approve that work

cpendery avatar Aug 04 '22 17:08 cpendery

  1. I am interested in contributing to:
  • [x] Development
  • [x] Documentation
  • [x] Issue triage and community
  • [ ] Technical advisory (review governance document)
  1. I am here because:
  • [x] Personal interest
  • [ ] My company/orgs I work with are interested in this
  1. ~~What is your associated company/org if you're contributing in their capacity? _________~~

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • [ ] Yes
  • [x] Maybe. Would be interested to stick with it so I can learn more about supply chain security 😃
  1. (optional) I have expertise in:
  • [ ] Neo4j
  • [ ] Cypher
  • [x] GraphQL (somewhat)
  • [ ] Intoto
  • [ ] SPDX
  • [ ] CycloneDX
  • [x] Others (fill in): HTML, CSS, JavaScript, Node.js, React, SQL. Open to expand my contribution/learning if more work is needed in any area of this project

shafeeshafee avatar Aug 05 '22 10:08 shafeeshafee

  1. I am interested in contributing to:
  • [X] Development
  • [ ] Documentation
  • [ ] Issue triage and community
  • [ ] Technical advisory (review governance document)
  1. I am here because:
  • [X] Personal interest
  • [ ] My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? _________

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • [X] Yes
  1. (optional) I have expertise in:
  • [ ] Neo4j
  • [ ] Cypher
  • [ ] GraphQL
  • [ ] Intoto
  • [ ] SPDX
  • [ ] CycloneDX
  • [X] Others (java, spring boot, mySql, mongodb, redis, golang, xml, json, rabbitmq, activemq, gcp):

Jhooomn avatar Aug 05 '22 20:08 Jhooomn

  1. I am interested in contributing to:
  • [x] Development
  • [x] Documentation
  • [x] Issue triage and community
  • [x] Technical advisory (review governance document)
  1. I am here because:
  • [x] Personal interest
  • [ ] My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? _Intel

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • [x] Yes
  1. (optional) I have expertise in:
  • [x] Neo4j
  • [x] Cypher
  • [ ] GraphQL
  • [ ] Intoto
  • [ ] SPDX
  • [x] CycloneDX
  • [ ] Others (fill in):

nadgowdas avatar Aug 17 '22 14:08 nadgowdas

btw we have a slack channel now! https://openssf.slack.com/archives/C03U677QD46 come join

lumjjb avatar Aug 19 '22 14:08 lumjjb

  1. I am interested in contributing to:
  • [x] Development
  • [x] Documentation
  • [x] Issue triage and community
  • [x] Technical advisory (review governance document)
  1. I am here because:
  • [x] Personal interest
  • [x] My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? ...stay tuned.

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • [x] Yes
  1. (optional) I have expertise in:
  • [x] Neo4j
  • [x] Cypher
  • [x] GraphQL
  • [ ] Intoto
  • [ ] SPDX
  • [ ] CycloneDX
  • [x] Others (fill in):
    • [x] cncf/landscape-graph
    • [x] cncf/tag-observability
    • [x] k8s, linkerd, operators, streaming, ci, gitops, dataThings, STRIDE, pride, compliance, ...
    • [x] Cirrus, Nimbostratus, Cumulonimbus, Stratocumulus, Mammatus, Orographic, Lenticular, and Contrails.

halcyondude avatar Aug 19 '22 20:08 halcyondude

  1. I am interested in contributing to:
  • [x] Development
  • [x] Documentation
  • [x] Issue triage and community
  • [x] Technical advisory (review governance document)
  1. I am here because:
  • [x] Personal interest
  • [ ] My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? _________

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • [x] Yes
  1. (optional) I have expertise in:
  • [ ] Neo4j
  • [ ] Cypher
  • [ ] GraphQL
  • [ ] Intoto
  • [ ] SPDX
  • [x] CycloneDX
  • [x] Others (fill in): Grype, Syft, Trivy, testing, CI

Note: my company may be interested in the project and me contributing in their capacity, so I'll update this note if they approve that work.

desenna avatar Sep 30 '22 03:09 desenna

  1. I am interested in contributing to:
  • [ ] Development
  • [x] Documentation
  • [x] Issue triage and community
  • [x] Technical advisory (review governance document)
  1. I am here because:
  • [x] Personal interest
  • [ ] My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? _________

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • [x] Yes
  1. (optional) I have expertise in:
  • [x] Neo4j
  • [ ] Cypher
  • [ ] GraphQL
  • [ ] Intoto
  • [ ] SPDX
  • [ ] CycloneDX
  • [ ] Others (fill in):

QAInsights avatar Oct 20 '22 18:10 QAInsights

  1. I am interested in contributing to:
  • [X] Development
  • [ ] Documentation
  • [X] Issue triage and community
  • [X] Technical advisory (review governance document)
  1. I am here because:
  • [X] Personal interest
  • [X] My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? https://haiphen.io__

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • [X] Yes
  1. (optional) I have expertise in:
  • [X] Neo4j
  • [X] Cypher
  • [X] GraphQL
  • [ ] Intoto
  • [X] SPDX
  • [ ] CycloneDX
  • [X] Others (fill in): ml, nlp, BERT, inductive GNN

JudeSafo avatar Oct 21 '22 20:10 JudeSafo

  1. I am interested in contributing to:
  • [ ] Development
  • [x] Documentation
  • [x] Issue triage and community
  • [x] Technical advisory (review governance document)
  1. I am here because:
  • [x] Personal interest
  • [ ] My company/orgs i work with are interested in this
  1. Depending on how things go, I may be interested in becoming a maintainer of the project
  • [x] Yes
  1. (optional) I have expertise in:
  • [x] Neo4j
  • [x] Cypher
  • [x] GraphQL
  • [ ] Intoto
  • [ ] SPDX
  • [x] CycloneDX
  • [ ] Others (fill in):

danielhaim1 avatar Oct 22 '22 06:10 danielhaim1

  1. I am interested in contributing to:
  • [ ] Development
  • [X] Documentation
  • [X] Issue triage and community
  • [X] Technical advisory (review governance document)
  1. I am here because:
  • [X] Personal interest
  • [ ] My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? _________

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • [X] Yes
  1. (optional) I have expertise in:
  • [ ] Neo4j
  • [ ] Cypher
  • [ ] GraphQL
  • [ ] Intoto
  • [ ] SPDX
  • [ ] CycloneDX
  • [ ] Others (fill in):

scpli3 avatar Oct 22 '22 12:10 scpli3

  1. I am interested in contributing to:
  • [ ] Development
  • [ ] Documentation
  • [ ] Issue triage and community
  • [x] Technical advisory (review governance document)
  1. I am here because:
  • [x] Personal interest
  • [ ] My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? N/A

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • [ ] Yes
  1. (optional) I have expertise in:
  • [x] Neo4j
  • [x] Cypher
  • [ ] GraphQL
  • [ ] Intoto
  • [x] SPDX
  • [x] CycloneDX
  • [x] Others (fill in): We designed and implemented a similar Security Graph Language (SGL) @SourceClear. The work was presented at IEEE SecDev 2018: SGL Slides SGL Paper

codelion avatar Oct 23 '22 11:10 codelion

  1. I am interested in contributing to:
  • [x] Development
  • [x] Documentation
  • [x] Issue triage and community
  • [x] Technical advisory (review governance document)
  1. I am here because:
  • [x] Personal interest
  • [ ] My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? _________

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • [ ] Yes
  1. (optional) I have expertise in:
  • [ ] Neo4j
  • [ ] Cypher
  • [ ] GraphQL
  • [ ] Intoto
  • [x] SPDX
  • [x] CycloneDX
  • [x] Others (fill in): Python

anthonyharrison avatar Oct 23 '22 13:10 anthonyharrison

  1. I am interested in contributing to:
  • [ ] Development
  • [x ] Documentation
  • [x ] Issue triage and community
  • [x ] Technical advisory (review governance document)
  1. I am here because:
  • [x ] Personal interest
  • [x ] My company/orgs I work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? Intel_______

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • [x ] Yes
  • [x ] Co-Maintainer
  1. (optional) I have expertise in:
  • [ ] Neo4j
  • [ ] Cypher
  • [ ] GraphQL
  • [ ] Intoto
  • [ ] SPDX
  • [ ] CycloneDX
  • [x ] Others (fill in):
  • [x ] Policy
  • [x ] Policy Shifted Left
  • [x ] SDLC Requirements
  • [x ] Risk Management
  • [x ] Compliance through SDLC
  • [x ] NIST 800-218
  • [x ] Smart aggregation turning data into meaning

sallienewton avatar Oct 23 '22 17:10 sallienewton

  1. I am interested in contributing to:
  • [X] Development
  • [X] Documentation
  • [ ] Issue triage and community
  • [X] Technical advisory (review governance document)
  1. I am here because:
  • [ ] Personal interest
  • [X] My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? Morphysm

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • [ ] Yes
  1. (optional) I have expertise in:
  • [X] Neo4j
  • [ ] Cypher
  • [X] GraphQL
  • [ ] Intoto
  • [X] SPDX
  • [ ] CycloneDX
  • [X] Go
  • [X] CodeQL

GreyXor avatar Oct 24 '22 13:10 GreyXor

  1. I am interested in contributing to:
  • [x] Development
  • [x] Documentation
  • [x] Issue triage and community
  • [ ] Technical advisory (review governance document)
  1. I am here because:
  • [x] Personal interest
  • [x] My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? _________

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • [ ] Yes
  1. (optional) I have expertise in:
  • [ ] Neo4j
  • [ ] Cypher
  • [ ] GraphQL
  • [ ] Intoto
  • [ ] SPDX
  • [ ] CycloneDX
  • [ ] Others (fill in): Python, C#, C++, HTML, PHP, MSSQL, Oracle, TypeScript, NodeJs, Bash, Batch, PowerShell

cepix1234 avatar Oct 24 '22 15:10 cepix1234

  1. I am interested in contributing to:
  • [x] Development
  • [x] Documentation
  • [x] Issue triage and community
  • [x] Technical advisory (review governance document)
  1. I am here because:
  • [x] Personal interest
  • [x] My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? FannieMae

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • [x] Yes
  1. (optional) I have expertise in:
  • [x] Neo4j
  • [ ] Cypher
  • [x] GraphQL
  • [ ] Intoto
  • [x] SPDX
  • [x] CycloneDX
  • [ ] Others (fill in): Java, TypeScript, Python, Bash

rvema avatar Oct 24 '22 17:10 rvema

  1. I am interested in contributing to:
  • [x] Development
  • [ ] Documentation
  • [x] Issue triage and community
  • [x] Technical advisory (review governance document)
  1. I am here because:
  • [x] Personal interest
  • [ ] My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? _________

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • [x] Yes
  1. (optional) I have expertise in:
  • [x] Neo4j
  • [x] Cypher
  • [x] GraphQL
  • [ ] Intoto
  • [ ] SPDX
  • [x] CycloneDX
  • [x] Others (fill in): Go, Rust, C/C++, JS, TS, Ruby, Bash, Python, WASM, HTML/CSS, SQL

ran-dall avatar Oct 25 '22 16:10 ran-dall

  1. I am interested in contributing to:
  • [x] Development
  • [ ] Documentation
  • [x] Issue triage and community
  • [x] Technical advisory (review governance document)
  1. I am here because:
  • [x] Personal interest
  • [x] My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? Crash Override

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • [x] Yes
  1. (optional) I have expertise in:
  • [x] Neo4j (familiarity)
  • [x] Cypher (familiarity)
  • [x] GraphQL (familiarity)
  • [ ] Intoto
  • [ ] SPDX
  • [x] CycloneDX (familiarity)
  • [x] Others (fill in): Python, Golang, C, LLVM, GCC, JS, TS, Bash, Python, HTML/CSS, SQL

nettrino avatar Oct 26 '22 18:10 nettrino

  1. I am interested in contributing to:
  • [x] Development
  • [x] Documentation
  • [x] Issue triage and community
  • [x] Technical advisory (review governance document)
  1. I am here because:
  • [x] Personal interest
  • [ ] My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? _NA

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • [x] Yes
  1. (optional) I have expertise in:
  • [ ] Neo4j
  • [ ] Cypher
  • [x] GraphQL
  • [ ] Intoto
  • [ ] SPDX
  • [ ] CycloneDX
  • [x] Developer Advocacy
  • [x] Platform Enabler
  • [x] Programming Distributed Systems & Design Internals
  • [x] Best practices, recommendations for cloud native applications for good.

mraipsec-mra avatar Oct 27 '22 00:10 mraipsec-mra

  1. I am interested in contributing to:
  • [x] Development
  • [ ] Documentation
  • [ ] Issue triage and community
  • [x] Technical advisory (review governance document)
  1. I am here because:
  • [ ] Personal interest
  • [x] My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? eBay

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • [x] Yes
  1. (optional) I have expertise in:
  • [ ] Neo4j
  • [ ] Cypher
  • [x] GraphQL
  • [ ] Intoto
  • [ ] SPDX
  • [ ] CycloneDX
  • [ ] Others (fill in):

justinabrahms avatar Oct 27 '22 15:10 justinabrahms

  1. I am interested in contributing to:
  • [X] Development
  • [X] Documentation
  • [ ] Issue triage and community
  • [X] Technical advisory (review governance document)
  1. I am here because:
  • [ ] Personal interest
  • [X] My company/orgs I work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? Seiso - cloud native security consulting. https:/sei.so

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • [X] Yes
  1. (optional) I have expertise in:
  • [ ] Neo4j
  • [X] Cypher
  • [ ] GraphQL
  • [X] Intoto (user)
  • [ ] SPDX
  • [ ] CycloneDX
  • [X] Others (fill in): Policy [as code], compliance automation, TAG-Security Controls, being pedantic

JonZeolla avatar Oct 27 '22 15:10 JonZeolla

  1. I am interested in contributing to:
  • [ x ] Development
  • [ x ] Documentation
  • [ ] Issue triage and community
  • [ ] Technical advisory (review governance document)
  1. I am here because:
  • [ X ] Personal interest
  • [ ] My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? _________

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • [ ] Yes
  1. (optional) I have expertise in:
  • [ X ] Neo4j
  • [ ] Cypher
  • [ ] GraphQL
  • [ ] Intoto
  • [ ] SPDX
  • [ X ] CycloneDX
  • [ ] Others (fill in):

tixu avatar Oct 31 '22 08:10 tixu

  1. I am interested in contributing to:
  • [ ] Development
  • [X ] Documentation
  • [ X] Issue triage and community
  • [ X] Technical advisory (review governance document)
  1. I am here because:
  • [ X] Personal interest
  • [ ] My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? _________

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • [X ] Yes
  1. (optional) I have expertise in:
  • [ ] Neo4j
  • [ ] Cypher
  • [ ] GraphQL
  • [ ] Intoto
  • [ ] SPDX
  • [ ] CycloneDX
  • [X ] Others (fill in): Python, Compliance, FedRAMP,

raj-andy1 avatar Oct 31 '22 17:10 raj-andy1

  1. I am interested in contributing to:
  • [x] Development
  • [x] Documentation
  • [x] Issue triage and community
  • [x] Technical advisory (review governance document)
  1. I am here because:
  • [x] Personal interest
  • [X] My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? Intuit

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • [x] Yes
  1. (optional) I have expertise in:
  • [x] Neo4j
  • [x] Cypher
  • [x] GraphQL
  • [ ] Intoto
  • [ ] SPDX
  • [ ] CycloneDX
  • [x] Others (fill in): Snyk, Artifactory

As one final note, my team is building an application that is much in the same vein as yours. We have a fairly mature project for modeling the infrastructure side. We are beginning to build new features around ingesting SBOM data and artifacts.

zprobst avatar Nov 01 '22 21:11 zprobst

  1. I am interested in contributing to:
  • [ ] Development
  • [x] Documentation
  • [x] Issue triage and community
  • [ ] Technical advisory (review governance document)
  1. I am here because:
  • [x] Personal interest
  • [ ] My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? _________

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • [ ] Yes
  1. (optional) I have expertise in:
  • [ ] Neo4j
  • [ ] Cypher
  • [ ] GraphQL
  • [ ] Intoto
  • [x] SPDX
  • [ ] CycloneDX
  • [x] Others (fill in): NIST 800-218, 800-161, SAMM, Secure SDLC, Third party risk, Product Security

raj-riskone avatar Nov 02 '22 16:11 raj-riskone

  1. I am interested in contributing to:
  • [x] Development
  • [x] Documentation
  • [x] Issue triage and community
  • [x] Technical advisory (review governance document)
  1. I am here because:
  • [x] Personal interest
  • [ ] My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? Raft

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • [x] Yes
  1. (optional) I have expertise in:
  • [ ] Neo4j
  • [ ] Cypher
  • [ ] GraphQL
  • [ ] Intoto
  • [ ] SPDX
  • [ ] CycloneDX
  • [ ] Others (fill in):

apmarshall avatar Nov 03 '22 10:11 apmarshall

  1. I am interested in contributing to:
  • [ ] Development
  • [x] Documentation
  • [ ] Issue triage and community
  • [ ] Technical advisory (review governance document)
  1. I am here because:
  • [x] Personal interest
  • [ ] My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? _________

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • [x] Yes
  1. (optional) I have expertise in:
  • [ ] Neo4j
  • [ ] Cypher
  • [ ] GraphQL
  • [ ] Intoto
  • [ ] SPDX
  • [ ] CycloneDX
  • [x] Others (fill in): Iac, Policy, Compliance, Python, Ascii Doc

rjain15 avatar Nov 03 '22 17:11 rjain15

Hi all! Thanks for expressing interest, we will probably be starting a series of community meetings soon! Information will be put here when they start - stay tuned! In the meantime, thanks for joining us!

lumjjb avatar Nov 03 '22 19:11 lumjjb

  1. I am interested in contributing to:
  • [x] Development
  • [x] Documentation
  • [x] Issue triage and community
  • [x] Technical advisory (review governance document)
  1. I am here because:
  • [x] Personal interest
  • [ ] My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? _________

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • [x] Yes
  1. (optional) I have expertise in:
  • [ ] Neo4j
  • [ ] Cypher
  • [ ] GraphQL
  • [ ] Intoto
  • [x] SPDX
  • [x] CycloneDX
  • [x] Others (fill in): development in general (Java, Go, Python), secure development, supply chain security

s-spindler avatar Nov 04 '22 12:11 s-spindler