FasterXML / FasterXML/jackson-core

Add SLSA provenance via build script

Open
#844 27 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
2.4k
Forks
928
Avg merge
2d 11h
Merged PRs (30d)
28

Description

Hey, I'm Pedro and I'm working on behalf of Google and the [Open Source Security Foundation][ossf] (OpenSSF). Given the significant [increase in supply-chain attacks][sonatype], the OpenSSF is focused on improving the security of the open-source ecosystem as a whole. For example, #792 was based on feedback from Scorecards, an OpenSSF tool.

The OpenSSF has also developed the [SLSA][slsa] specification for projects to attest to a published artifact's provenance, allowing its consumers to ensure that the artifact comes from a trusted source. There are also GitHub workflows to securely generate this provenance and CLI tools to verify an artifact's authenticity.

Given how Jackson is almost synonymous with JSON in the Java ecosystem, the OpenSSF has placed Jackson on its list of the 100 most important open-source projects. I'd therefore like to offer to help jackson-core incorporate SLSA into its deploy workflow.

Would you be interested in a PR to adopt SLSA?

[ossf]: https://openssf.org/
[slsa]: https://slsa.dev/
[sonatype]: https://www.sonatype.com/state-of-the-software-supply-chain/introduction

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.