-
Notifications
You must be signed in to change notification settings - Fork 61
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add 2025 Q1 Securing Repos WG update #444
base: main
Are you sure you want to change the base?
Conversation
Signed-off-by: Zach Steindler <[email protected]>
Signed-off-by: Zach Steindler <[email protected]>
Should we add the Central sigstore validation as an update? (https://www.sonatype.com/blog/central-publisher-portal-now-validates-sigstore-signatures) |
Signed-off-by: Zach Steindler <[email protected]>
It has now been added - thanks! |
Provide a service to protect repository index from tampering by distributing them with The Update Framework (TUF) | ||
|
||
### Current Status | ||
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
RSTUF is starting the security audit from 3rd February 2025
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Is this in support of upcoming project graduation? Or do you expect that is still farther out?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Added the start date - thanks!
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@kairoaraujo can correct me if I'm wrong, but I don't think we're in a particular hurry for RSTUF project graduation. For now we want to focus on standing it up for RubyGems and PyPI and demonstrate its usefulness.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The RSTUF project's focus right now is getting the security audit, release 1.0.0 final, and asking OpenSSF support to promote the project, from helping public repositories (PyPI, RubyGems, Crates, etc) to going beyond and showing organizations how to secure their content distribution.
The success of this phase, IMHO, is the guarantee that this project can go to the graduation.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
That sounds great! I think it makes sense to defer graduation until there's more adoption.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM except for one item that's unclear.
Signed-off-by: Zach Steindler <[email protected]>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM. Thanks!
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks @steiza ! I have a couple of questions/comments.
|
||
- Hire contractor; publish package yanking guidance | ||
- [Funding request: UI/UX support for attestations on software repos](https://github.com/ossf/tac/issues/424) | ||
- Continue supporting landing security capabilities in software repositories |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Are you targeting specific ones in the coming quarter?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The somewhat-glib answer is whoever shows up and wants to work together! A more helpful answer is that we're tracking security capabilities in progress across many ecosystems with work in progress or proposed in PyPI, RubyGems, NuGet, and Rust Crates. Last week we had a promising early conversation with Conda Forge about potential future collaborations.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
That's really great to hear! Whatever you're able to share about the ecosystems you're tracking and/or are hoping to collaborate with would be a great addition here :)
Provide a service to protect repository index from tampering by distributing them with The Update Framework (TUF) | ||
|
||
### Current Status | ||
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Is this in support of upcoming project graduation? Or do you expect that is still farther out?
Signed-off-by: Zach Steindler <[email protected]>
For the upcoming TAC meeting Tuesday Feb 4th