slsa icon indicating copy to clipboard operation
slsa copied to clipboard

Positioning SIG: Define/Expand Scope and Charter

Open melba-lopez opened this issue 3 years ago • 3 comments

Background: “Government and industry widely accept SLSA as the lingua franca of supply chain security”

Objective: Expand on original defined Charter and define scope for the Positioning SIG per 7/26 Meeting.

Outcomes:
- [ ] Clearly defined, documented, and approved Charter for Positioning SIG - [ ] Clearly defined, documented, and approved Scope for Positioning SIG - [ ] Centrally Published Charter/Scope for Positioning SIG

melba-lopez avatar Jul 28 '22 19:07 melba-lopez

8/9 Meeting

Brandon - Evaluation of slsa against other efforts ( issue #452 ) , to better inform the specification and tooling. **Jeff ** - External component to describing issue #452 Jason +1 ^^^ - compare and communicate differences in security standards issue #452 (how it fits/overlaps/etc) Bruno - Visibility - MAS example -- bridge SLSA with things that it can be applied to (who have to check/provide artifacts) **Melba ** - Clarity on how slsa impacts other GEOs and their (country) regulations/standards.
Jay - identifying the audience (producer vs consumer); SLSA is more focused on the producer of services; maybe we need a standard for the consumers of SLSA ; bridge the two to achieve better security/compliance

melba-lopez avatar Aug 09 '22 18:08 melba-lopez

Created Draft Charter - Please review by 8/30!! https://docs.google.com/document/d/1mmvPsfqg8upg9QSK1Xm9XN1W9njkWa6ZHpAEqdKJ9ds/edit#

melba-lopez avatar Aug 23 '22 19:08 melba-lopez

Opened PR https://github.com/slsa-framework/governance/pull/15

melba-lopez avatar Oct 04 '22 17:10 melba-lopez