Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Bug] Fix '/supply-chain-security/compromises' 404 (with redirect) #1357

Open
maltfield opened this issue Aug 29, 2024 · 1 comment
Open
Assignees
Labels
good first issue Good for newcomers suggestion New suggestion for the CNCF sig-security group that don't fall into an existing category

Comments

@maltfield
Copy link

This ticket is to report that one of my favoriate bookmarked links (to this repo) is now a 404

Problem

I frequently send the above link to many people, but now it gives a 404 :(

In the past many years, I've opened countless bug reports with developers (on GitHub and elsewhere) asking them to improve the security of their release process to provide a means for their users to have some protection against supply chain compromises.

Not all developers have an inherent understanding of why it's important to, for example, cryptographically sign their releases. For many, you need to point the developer to a list of historical events where supply chain compromises have actually happened in the real world. Only then will many understand the importance of supply chain security.

Solution

Unfortunately, all these old tickets that I've created that link to this repo are now broken. Note that many of these tickets are still open/pending tasks, so I think it's important that the information is still available.

I don't know where the supply-chain-security/compromises list has been moved, but I don't think a solution to this ticket is to tell me where it now lives.

The solution to this ticket is to recreate the file supply-chain-security/compromises at HEAD with a message that inclues a link to the new location of the supply-chain-security/compromises list.

@maltfield maltfield added suggestion New suggestion for the CNCF sig-security group that don't fall into an existing category triage-required Requires triage labels Aug 29, 2024
@maltfield
Copy link
Author

fyi, it looks like the redirect link should point to https://github.com/cncf/tag-security/tree/main/community/catalog/compromises

@mnm678 mnm678 added the good first issue Good for newcomers label Sep 20, 2024
@jkjell jkjell removed the triage-required Requires triage label Oct 30, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
good first issue Good for newcomers suggestion New suggestion for the CNCF sig-security group that don't fall into an existing category
Projects
None yet
Development

No branches or pull requests

4 participants