Skip to content

Latest commit

 

History

History
64 lines (46 loc) · 2.48 KB

File metadata and controls

64 lines (46 loc) · 2.48 KB

Supply Chain Maturity Model Workstream README

This is a workstream within the CDF SIG Software Supply Chain.

The forming of this workstream was suggested at a recent SIG Software Supply Chain meeting

Scope

The workstream will cover CICD beyond build and deploy.

Mission

The workstream seeks to define industry standards for Supply Chain Maturity that augment SLSA. Where SLSA covers the supply chain from code through artifact, maturity covers the artifact lifecycle, including deployments, rollouts, testing, rollbacks, and more.

The workstream seeks to define an industry standard to augment SLSA.

Proposed names so far include:

  • Code Health Project Score ("CHiPS") (but it conflicts with CHIPS Alliance under the Linux Foundation)
  • Guide for Understanding Application Concerns ("GUAC")

Our first priority will be to identify additional clever retronyms and settle on a memorable name.

Members

Current members:

  • David Bendory, Google
  • Justin Abrahms, eBay/CDF
  • Ankit D Mohapatra, Berkshire Grey
  • Parth Patel, Kusari
  • Kara de la Marck, CDF
  • David Espejo, VMware
  • <your-name-here!>

Membership to this workstream is open and self-declared.

New members are invited to:

Communication Channels

Please join our Slack channel on CDF Slack.

Meetings

Supply Chain Maturity workstream meetings: