philips-software / philips-software/amp-devcontainer
Document compliance with SLSA Level 3
Open
Nobody has claimed this yet.
- Dominant language
- Shell
- Stars
- 135
- Forks
- 8
- Avg merge
- 2d 5h
- Merged PRs (30d)
- 28
Description
Current situation
Supply chain security and provenance is a priority for amp-devcontainer, but no formal assessment against the SLSA framework has been conducted.
Required situation
Documented compliance with SLSA Level 3 is available, and a roadmap to become SLSA Level 4 compliant is in-place.
Acceptance criteria
- Requirements are updated with the targeted SLSA version and level
- Compliance is documented and linked, where possible, with the corresponding requirements and tests
- SLSA badge is added to the README
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing the repository's existing requirements and tests, then compare them with the SLSA v1.2 Level 3 requirements. Document the compliance mapping and Level 4 roadmap, update the targeted requirements, and add the SLSA badge to the README.
Written by the indexing model from the issue text.
Assessment
- Domain
- devops, documentation, security
- Issue type
- Documentation
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100