[Proposal] [Supply Chain Security] [Compromises Catalog] not-a-compromise.md #1348
Open
1 of 19 tasks
Labels
proposal
common precursor to project, for discussion & scoping
supplychain
triage-required
Requires triage
Description: Maintain a list of incidents that were assessed but do not meet the definition of a software supply chain security compromise
Impact: It helps the industry and the community be precise in their definition of software supply chain security compromises by describing prime examples that are NOT a software supply chain security compromise, regardless of their impact and visibility
Scope: A new append-only Markdown file under
supply-chain-security/compromises
callednot-a-compromise.md
with a very simple structure: year, URL(s), and a description of why it doesn't meet the definition.Intent to lead:
interested in pursing this work. This statement of intent does not preclude
others from co-leading or becoming lead in my stead.
Proposal to Project:
This proposal is being raised on GitHub Issues.
lead
with call for participation in #tag-security slack channel thread add link
and mailing list email add link
TO DO
Happy to take the discussion to the appropriate forum, but planning for that to be GitHub Issues for now. I intend to follow up with a PR bootstrapping this idea.
Representative
see progress!
The text was updated successfully, but these errors were encountered: