Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Want to work with CNCF Supply Chain Security WG to make SPIRE an example of best practice? #5783

Open
kipz opened this issue Jan 16, 2025 · 0 comments
Labels
triage/in-progress Issue triage is in progress

Comments

@kipz
Copy link

kipz commented Jan 16, 2025

Over at the CNCF TAG Security - Supply Chain Security WG, we're looking for a CNCF project to be an example of supply chain security best practice to point people to, and SPIRE came up at the last meeting as a potential candidate.

I brought this up in Slack and was directed to raise it here.

We recently published an updated version of our whitepaper.

Is there appetite in this community to collaborate on this? We've not done this before, so we'll need to figure out what works, but I suspect we'd need to have someone on point from SPIRE and someone from the Supply Chain WG (possibly myself) to first figure out the gaps (if any), and then work together to fill some of them. Culminating perhaps with a blog or something detailing the journey?

If there's interested in this, it would be much appreciated, and could bring the benefit of reducing the supply chain risk for this project, and ultimately others in the ecosystem!

Come find us in Slack

@rturner3 rturner3 added the triage/in-progress Issue triage is in progress label Jan 16, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
triage/in-progress Issue triage is in progress
Projects
None yet
Development

No branches or pull requests

2 participants