adoptium / adoptium/infrastructure

SSDF PO.3.2 Documentation on maintainance and security of toolchains

Open
#2,553 3 comments 0 reactions 0 assignees View on GitHub
security
Dominant language
Python
Stars
96
Forks
106
Avg merge
1d 23h
Merged PRs (30d)
13

Description

Part of https://github.com/adoptium/adoptium/issues/122:

## PO.3.2 Follow recommended security practices to deploy, operate, and maintain tools and toolchains

- Compose and maintain process documentation on each toolchain’s workflow and how the tools integrate with each other.
- Compose and maintain process documentation on how to securely configure and use each tool in the toolchain.
- Compose and maintain process documentation on how the tools collect evidence in support of secure development practices.

Contributor guide

Open the contributing guide

Research direction

The issue names no files, tests, or toolchain entry points. Start by reviewing parent issue #122 and identifying the toolchains covered; done means documenting each toolchain’s workflow, tool integration, secure configuration and use, and evidence collection.

Written by the indexing model from the issue text.

Assessment

Domain
devops, documentation
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.