Proposal: Add KubeArmor SLSA L3 and OpenSSF Scorecard Hardening (LFX Term 2)#1870
Conversation
Added a new project idea for KubeArmor focusing on supply chain security compliance and OpenSSF Scorecard improvements, including detailed expected outcomes and required skills. Signed-off-by: Atharva Shah <68660002+HighnessAtharva@users.noreply.github.com>
|
Thanks for this @HighnessAtharva! @rootxrishabh @daemon1024 @nyrahul @rksharma95, could you each approve or 👍 this PR to confirm your (and the project's) participation? |
Signed-off-by: Nate W <natew@cncf.io>
Signed-off-by: Nate W <natew@cncf.io>
|
LFX URL: Followup, we only need 1 upstream issue in order to load this into the LFX platform. I'll add the first one listed, but if you'd like to update this with an umbrella issue I can make an update. |
Yes please, that would be great. Also we'd like to add @AryanBakliwal to the list of mentors. |
Please open a followup PR to make that update in the README. |
|
You already have 4 mentors, 5 is a lot, can I ask why the program needs so many? (I do appreciate the enthusiasm, but I'd like to make sure that we're not overwhelming the mentee, and that each mentor has a role to play) |
Adds a new mentorship project idea for KubeArmor covering SLSA Level 3 compliance and OpenSSF Scorecard hardening. The two tasks are combined into a single mentorship scope as they share overlapping mechanics around signed releases, build provenance, and artifact integrity.
Pre-task: Signed-Releases check via OpenSSF Scorecard.
CC: @rootxrishabh @daemon1024 @nyrahul @rksharma95
Reviewers: @nate-double-u