Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add 2025 Q1 Securing Repos WG update #444

Open
wants to merge 5 commits into
base: main
Choose a base branch
from
Open

Add 2025 Q1 Securing Repos WG update #444

wants to merge 5 commits into from

Conversation

steiza
Copy link
Member

@steiza steiza commented Jan 29, 2025

For the upcoming TAC meeting Tuesday Feb 4th

@steiza steiza requested a review from a team as a code owner January 29, 2025 15:01
Signed-off-by: Zach Steindler <[email protected]>
@brianf
Copy link

brianf commented Jan 29, 2025

Should we add the Central sigstore validation as an update? (https://www.sonatype.com/blog/central-publisher-portal-now-validates-sigstore-signatures)

@steiza
Copy link
Member Author

steiza commented Jan 29, 2025

Should we add the Central sigstore validation as an update? (https://www.sonatype.com/blog/central-publisher-portal-now-validates-sigstore-signatures)

It has now been added - thanks!

Provide a service to protect repository index from tampering by distributing them with The Update Framework (TUF)

### Current Status

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

RSTUF is starting the security audit from 3rd February 2025

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is this in support of upcoming project graduation? Or do you expect that is still farther out?

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added the start date - thanks!

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@kairoaraujo can correct me if I'm wrong, but I don't think we're in a particular hurry for RSTUF project graduation. For now we want to focus on standing it up for RubyGems and PyPI and demonstrate its usefulness.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi @steiza, @marcelamelara

The RSTUF project's focus right now is getting the security audit, release 1.0.0 final, and asking OpenSSF support to promote the project, from helping public repositories (PyPI, RubyGems, Crates, etc) to going beyond and showing organizations how to secure their content distribution.

The success of this phase, IMHO, is the guarantee that this project can go to the graduation.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That sounds great! I think it makes sense to defer graduation until there's more adoption.

Copy link
Contributor

@lehors lehors left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM except for one item that's unclear.

TI-reports/2025/2025-Q1-Repos-WG.md Outdated Show resolved Hide resolved
Signed-off-by: Zach Steindler <[email protected]>
Copy link
Contributor

@lehors lehors left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks!

Copy link
Contributor

@marcelamelara marcelamelara left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @steiza ! I have a couple of questions/comments.

TI-reports/2025/2025-Q1-Repos-WG.md Outdated Show resolved Hide resolved

- Hire contractor; publish package yanking guidance
- [Funding request: UI/UX support for attestations on software repos](https://github.com/ossf/tac/issues/424)
- Continue supporting landing security capabilities in software repositories
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Are you targeting specific ones in the coming quarter?

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The somewhat-glib answer is whoever shows up and wants to work together! A more helpful answer is that we're tracking security capabilities in progress across many ecosystems with work in progress or proposed in PyPI, RubyGems, NuGet, and Rust Crates. Last week we had a promising early conversation with Conda Forge about potential future collaborations.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That's really great to hear! Whatever you're able to share about the ecosystems you're tracking and/or are hoping to collaborate with would be a great addition here :)

Provide a service to protect repository index from tampering by distributing them with The Update Framework (TUF)

### Current Status

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is this in support of upcoming project graduation? Or do you expect that is still farther out?

Signed-off-by: Zach Steindler <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

6 participants