Skip to content

Conversation

@mrdavidlaing
Copy link
Contributor

Implementation Plan

This PR implements a curated Nix package set with enterprise compliance features:

Scope: 10 curated packages (go, opencode, git, gh, jq, ripgrep, grep, findutils, gawk, gnused)
Compliance: CycloneDX SBOMs → GitHub Security, SLSA Level 3 provenance, CVE triage workflows
Delivery: Nix flake + .devcontainer for VS Code

Key Features

  • ✅ CycloneDX SBOM generation on release
  • ✅ SLSA Level 3 build provenance attestations
  • ✅ GitHub Security CVE integration
  • ✅ Automated CVE triage workflows
  • ✅ Binary cache via Cachix

Execution Waves

  1. Foundation: flake.nix, 10 package derivations, devcontainer
  2. Compliance: SBOM workflow, SLSA provenance, binary cache
  3. Integration: CVE triage, documentation

Status

  • Wave 1: Foundation
  • Wave 2: Compliance
  • Wave 3: Integration
  • Ready for review

Plan approved by Prometheus + Metis + Momus

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant