Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Use LFX Security Platform #13

Open
tsteenbe opened this issue Jan 28, 2021 · 3 comments
Open

Use LFX Security Platform #13

tsteenbe opened this issue Jan 28, 2021 · 3 comments
Assignees

Comments

@tsteenbe
Copy link
Member

ORT could also apply LFX Security Platform, to do so we need to provide below data:

ributors of your team who can also benefit from fund raise) -> Contributor Name + Contributor Email for each core contributor

LFX Security Platform decisions to be made by ORT TSC:
2. Do we also want to apply LF Security Platform? (Get Snyk scans for ORT)
If yes, then:
A. What is our project color?
B. In which category do we want to be listed? Dependency Management or ...?
C. What is our elevator pitch?
D. Do we want to apply for a CII badge?

@sschuberth
Copy link
Member

In a video call this morning I learned from @ShubhraKar that LFX is not only about security, but also about Insights. I've enrolled ORT to get some nice statistics and visibility on the LFX platform.

Regarding security, I guess nothing speaks against signing up to that service, too. I also learned that Snyk seems to provide special conditions to LF projects in general, not just LFX, so we should check with @ShubhraKar to integrate Snyk into ORT as an advisor.

@sschuberth
Copy link
Member

sschuberth commented Feb 25, 2021

@sschuberth sschuberth changed the title Use LFX Security Platform? Use LFX Security Platform Feb 25, 2021
@sschuberth sschuberth self-assigned this Feb 26, 2021
@sschuberth
Copy link
Member

The Insights page for ORT is live: https://insights.lfx.linuxfoundation.org/projects/act%2Fort/dashboard

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants