Jira (PUP-11657) General improvements on security

7 views
Skip to first unread message

Diogo Teles Sant anna (Jira)

unread,
Oct 17, 2022, 4:54:01 PM10/17/22
to puppe...@googlegroups.com
Diogo Teles Sant anna created an issue
 
Puppet / Improvement PUP-11657
General improvements on security
Issue Type: Improvement Improvement
Assignee: Unassigned
Created: 2022/10/17 1:53 PM
Priority: Low Low
Reporter: Diogo Teles Sant anna

Hello! Given the current scenario of increasing attacks on supply chain projects, Google (in partnership with the [Open Source Security Foundation](https://openssf.org/)) has hired me to work around important open-source projects to help increase security, in any aspect or concern that might be relevant.

I'm talking to you because `puppetlabs/puppet` has reached a significant importance and impact, so I would like to make myself available to help with any security concern or discussion you might have.

I see that you are already concerned about security, so in case you don't have any pendencies that I could help with, I could create a PR to add the GitHub Action of [Scorecards](https://securityscorecards.dev/) to your project. This would help you to easily track possible vulnerabilities and security pendencies over your code.

Let me know if you have any further questions.

OBS: sorry if I did not fill the Jira ticket appropriately, I was not really sure how to do it considering this atypical "Issue".

Thanks for the attention =)

Add Comment Add Comment
 
This message was sent by Atlassian Jira (v8.20.11#820011-sha1:0629dd8)
Atlassian logo

Morgan Rhodes (Jira)

unread,
Oct 18, 2022, 4:46:03 PM10/18/22
to puppe...@googlegroups.com
Morgan Rhodes updated an issue
Change By: Morgan Rhodes
Team: Comply EMEA

Jeremy Mill (Jira)

unread,
Oct 19, 2022, 8:58:03 AM10/19/22
to puppe...@googlegroups.com
Jeremy Mill assigned an issue to Jeremy Mill
Change By: Jeremy Mill
Assignee: Jeremy Mill

Jeremy Mill (Jira)

unread,
Oct 24, 2022, 8:17:01 AM10/24/22
to puppe...@googlegroups.com
Jeremy Mill commented on Improvement PUP-11657
 
Re: General improvements on security

Hey Diego,

Unfortunately the security scorecard PR isn't something we're interested in integrating right now. Our application security program covers all of the tenants but sometimes in a way that it can't be reflected on the OSS repo. Thank you for reaching out and we'll let you know if we decide otherwise in the future!

-The Puppet Sec Team

Reply all
Reply to author
Forward
0 new messages