Skip to content

Outreachy: Secure Software Supply Chain Enhancements: Project RASPberry

Shelley Lambert edited this page Nov 29, 2022 · 5 revisions

Project Description

This project entails improving our 'R'eproducibility, 'A'uditability, 'S'ecurity, and 'P'resentability (RASP) of our product builds through enhancing our approach to tracking dependencies. We will now like to move this metadata and information to a more standardized form of SBOM (secure bill of materials). Investigation and prototyping to create a CycloneDX SBOM that describes our binaries will be a major piece of this project. This effort directly helps us to have a more transparent and auditable build process and increase confidence of our consumers that we have a secure software supply chain.

Some learning materials that will be useful

Read about why SBOMs are important:

Review CycloneDX learning materials and documentation:

Look at some of the completed and on-going issues to support reproducible builds

Project RASPberry Q&A session

Participants

Intern: Sehrish Aslam

Mentors: Andrew Leonard, Stewart Addison and Shelley Lambert