Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Workstream: Build Platform Operations Track #985

Open
MarkLodato opened this issue Oct 11, 2023 · 0 comments
Open

Workstream: Build Platform Operations Track #985

MarkLodato opened this issue Oct 11, 2023 · 0 comments
Labels
workstream Major effort comprising multiple sub-issues

Comments

@MarkLodato
Copy link
Member

MarkLodato commented Oct 11, 2023

This is a tracking issue for creating a Build Platform Operations track. The main idea is to cover the trust in the build platform itself. Whereas the Build track covers the application-level behavior of the build platform, this covers the generic operation (not really specific to build).

Project shepherd: UNASSIGNED (no active development currently)

Related: We might want to merge with #975 (hardware attested builds) and/or #977 (Build L4, discussing reproducible builds) as discussed in #975 (comment).

Sub-issues:

  • (none so far)

/cc @mattfarina

See also: #802

v0.1 had a brief mention of this concept, but it was never fleshed out and was ultimately deferred in v1.0. This seems like an important concept but we're currently unclear how to fit it into SLSA. Should it be a separate track? Should it be folded into the existing track? Should it not be a track at all but instead be some sort of guidance? This all needs to be fleshed out.

Also, is this really specific to Builds, or should this just be "Platform Operations" that are common to any trusted system of the supply chain?

@MarkLodato MarkLodato added the workstream Major effort comprising multiple sub-issues label Oct 11, 2023
@github-project-automation github-project-automation bot moved this to 🆕 New in Issue triage Oct 11, 2023
@MarkLodato MarkLodato changed the title Project Project: Build Operations Track Oct 11, 2023
@MarkLodato MarkLodato changed the title Project: Build Operations Track Project: Build Platform Operations Track Oct 11, 2023
@marcelamelara marcelamelara changed the title Project: Build Platform Operations Track Workstream: Build Platform Operations Track Oct 16, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
workstream Major effort comprising multiple sub-issues
Projects
Status: 🆕 New
Development

No branches or pull requests

1 participant