hackforla / hackforla/lucky-parking
Define container security and software-bill-of-materials approach
- Dominant language
- Jupyter Notebook
- Stars
- 37
- Forks
- 60
- Avg merge
- 13h 32m
- Merged PRs (30d)
- 5
Description
### Description
Evaluate security controls for container images and produced artifacts if the project publishes or deploys Docker images.
### Action Items
- [ ] Confirm whether Docker images are built only locally or are published/deployed, and identify registries and consumers.
- [ ] Inventory current Dockerfiles, base images, build process, and artifact ownership.
- [ ] Evaluate image vulnerability scanning, SBOM generation, base-image update policy, and provenance/attestation options.
- [ ] Define severity thresholds, exception process, remediation ownership, and CI cost/runtime impact.
- [ ] Produce an approved phased implementation plan before adding required scans or publishing security artifacts.
### Additional Information
Status: Triage — only relevant if container images are distributed or deployed. Refine the deployment context and ownership first; do not add tools or required gates prematurely.
Contributor guide
Research direction
Start by confirming whether this project publishes or deploys Docker images, then inventory the Dockerfiles, base images, build process, registries, consumers, and artifact ownership. Evaluate scanning, SBOM, update, provenance, severity, exception, and ownership options; done means an approved phased implementation plan exists without prematurely adding tools or required gates.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- docker, dockerfile
- Domain
- devops, infrastructure, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 30/100