Grafeas Update for Community

199 views
Skip to first unread message

Aysylu Greenberg

unread,
Feb 11, 2019, 1:32:46 PM2/11/19
to Grafeas Users

Grafeas Community,


I'm Aysylu Greenberg, the lead of Grafeas and Kritis projects at Google. I met with some of you a few months ago, on Nov 27, 2018, to discuss the future directions of Grafeas. I'd like to update the whole community on where Grafeas is headed and what we plan for it in the year of 2019 and going forward.


We will pursue 2 goals for Grafeas:

  1. Grafeas is the Open Source standard for storing and retrieving metadata about software resources. There is a need for such a standard, and we intend on making it universally useful in the software supply chain domain.

  2. Use Grafeas anywhere. Many of our users need hybrid cloud solutions, so having both options will enable them to use Grafeas anywhere. Grafeas is already available as a GCP-hosted (Container Analysis) and we plan to make it an on-premises solution as well.


All of the proposed features in GH issues are considered and prioritized. So please continue contributing them! And if you'd like to contribute code and you are unsure where to start, look for issues labeled "good first issue". The prioritization is currently as follows:

  • Short-term:

    • On-prem support for Kritis, which drives support for on-prem Grafeas;

    • Idiomatic Go client library for Grafeas.

  • Mid- and long-term:

    • Move towards achieving the 2 goals with the feedback from the community and the wider industry.


We look forward to collaborating with you and all your feedback!


Cheers,

Aysylu

Balázs Gyurák

unread,
May 20, 2020, 7:23:39 AM5/20/20
to Grafeas Users
Hi Aysylu,

My company and I are currently investigating Grafeas & Kritis for using it in our internal CI/CD pipelines. We are very interested to learn more about the short/long term plans. I have the following specific questions:

  1. What are your timelines for moving over the "v1" API, for both Grafeas and Kritis? Is this viable in the near future (2-3 months), or is it further down the line?
  2. Do you have a more specific roadmap, other than what you mentioned? We are very interested to learn about the specifics of the two mentioned goals. We'd like to get a sense of the current state and the available resources of the project.
  3. Could you please share more details about the on-prem Grafeas and on-prem Kritis? What does this mean exactly and how do you envision this? Would it be a fork, or a paid-for support model?
  4. We are considering implementing Grafeas from scratch in the .NET ecosystem, and would potentially contribute it back to the community. Is this something you would consider? I know you are actively looking for contributions for the current implementation, but I'm not sure if you would like to include a completely separate implementation.
  5. I've seen in this group that there were some community calls in the past - do you have something similar scheduled in the near future? If so, I would like to attend - will it be announced on this forum beforehand?
Thank you and the other contributors for your work on these tools - they are very promising and will fill a much-needed gap.

Thanks,
Balazs
Reply all
Reply to author
Forward
0 new messages