gemaraproj / gemaraproj/community
docs(proposal): create reusable artifact contribution guide
- Dominant language
- No language data
- Stars
- 1
- Forks
- 1
- Avg merge
- 1d 4h
- Merged PRs (30d)
- 1
Description
## Description
The Gemara schemas are already used to express Control Catalogs, Threat Catalogs, and Guidance Catalogs across the [FINOS CCC](https://github.com/finos/common-cloud-controls/tree/main/catalogs/core/core) & [OSPS Baseline](https://github.com/ossf/security-baseline/tree/main/baseline) projects. The procedure for proposing reusable catalogs is not documented. Therefore, it's difficult for contributors to essentially "donate" catalogs to the ecosystem because there isn't a centralized place for finding reusable catalogs.
## Expected Solution
Create a guide and set of criteria for contributors to share reusable catalogs to the Gemara ecosystem.
## Things to Consider
1. What makes a Catalog within the 7-layer architecture "reusable?"
2. What level of review must be completed to ensure the proposed Catalog(s) are accurate apart from schema-validation?
3. What is the maintenance cycle for the Catalog(s)?
## Supporting Resources
* Discussion in the community looking to donate catalogs
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.