hackforla / hackforla/lucky-parking

Define container security and software-bill-of-materials approach

Open
#754 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Jupyter Notebook
Stars
37
Forks
60
Avg merge
13h 32m
Merged PRs (30d)
5

Description

### Description

Evaluate security controls for container images and produced artifacts if the project publishes or deploys Docker images.

### Action Items

- [ ] Confirm whether Docker images are built only locally or are published/deployed, and identify registries and consumers.
- [ ] Inventory current Dockerfiles, base images, build process, and artifact ownership.
- [ ] Evaluate image vulnerability scanning, SBOM generation, base-image update policy, and provenance/attestation options.
- [ ] Define severity thresholds, exception process, remediation ownership, and CI cost/runtime impact.
- [ ] Produce an approved phased implementation plan before adding required scans or publishing security artifacts.

### Additional Information

Status: Triage — only relevant if container images are distributed or deployed. Refine the deployment context and ownership first; do not add tools or required gates prematurely.

Contributor guide

Open the contributing guide

Research direction

Start by confirming whether this project publishes or deploys Docker images, then inventory the Dockerfiles, base images, build process, registries, consumers, and artifact ownership. Evaluate scanning, SBOM, update, provenance, severity, exception, and ownership options; done means an approved phased implementation plan exists without prematurely adding tools or required gates.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker, dockerfile
Domain
devops, infrastructure, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.