gemaraproj / gemaraproj/community

docs(proposal): create reusable artifact contribution guide

Open
#8 0 comments 0 reactions 1 assignee Claimed by @hbraswelrh View on GitHub
documentation enhancement
Dominant language
No language data
Stars
1
Forks
1
Avg merge
1d 4h
Merged PRs (30d)
1

Description

## Description

The Gemara schemas are already used to express Control Catalogs, Threat Catalogs, and Guidance Catalogs across the [FINOS CCC](https://github.com/finos/common-cloud-controls/tree/main/catalogs/core/core) & [OSPS Baseline](https://github.com/ossf/security-baseline/tree/main/baseline) projects. The procedure for proposing reusable catalogs is not documented. Therefore, it's difficult for contributors to essentially "donate" catalogs to the ecosystem because there isn't a centralized place for finding reusable catalogs.

## Expected Solution

Create a guide and set of criteria for contributors to share reusable catalogs to the Gemara ecosystem.

## Things to Consider

1. What makes a Catalog within the 7-layer architecture "reusable?"
2. What level of review must be completed to ensure the proposed Catalog(s) are accurate apart from schema-validation?
3. What is the maintenance cycle for the Catalog(s)?

## Supporting Resources

* Discussion in the community looking to donate catalogs

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.