adoptium / adoptium/infrastructure
SSDF PO.3.2 Documentation on maintainance and security of toolchains
- Dominant language
- Python
- Stars
- 96
- Forks
- 106
- Avg merge
- 1d 23h
- Merged PRs (30d)
- 13
Description
Part of https://github.com/adoptium/adoptium/issues/122:
## PO.3.2 Follow recommended security practices to deploy, operate, and maintain tools and toolchains
- Compose and maintain process documentation on each toolchain’s workflow and how the tools integrate with each other.
- Compose and maintain process documentation on how to securely configure and use each tool in the toolchain.
- Compose and maintain process documentation on how the tools collect evidence in support of secure development practices.
Contributor guide
Research direction
The issue names no files, tests, or toolchain entry points. Start by reviewing parent issue #122 and identifying the toolchains covered; done means documenting each toolchain’s workflow, tool integration, secure configuration and use, and evidence collection.
Written by the indexing model from the issue text.
Assessment
- Domain
- devops, documentation
- Issue type
- Documentation
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100