Fetching the latest programs, projects, and workspace data.
Help contributors get started with improving the documentation of CNCF projects and TAGs. To start, we'd like mentees to help to improve both the documentation of a project, and also encourage them to contribute to other projects. So, view the issues as a starting point to help start your career in open source. Expected Outcome: Develop effective documentation for CNCF projects. As a start, the CNCF project in-toto has a fairly clear set of requirements for what documentation changes are needed.
Showing 3 of 3 projects. Click any project card for scope, mentors, and proposal studio.
The project aims to integrate Graph for Understanding Artifact Composition (GUAC) with in-toto, a framework safeguarding software supply chain integrity. Graph for Understanding Artifact Composition (GUAC) aggregates software security metadata into a high fidelity graph database—normalizing entity identities and mapping standard relationships between them. This project seeks to extend in-toto's capabilities by incorporating GUAC, enabling users to query GUAC with Package URLs (purls) and retrieve pertinent attestations. Expected Outcome: Adds functionality to query GUAC, retrieve and parse relevant attestations for the specified artifact.
The in-toto Jenkins plugin allows users to generate metadata in their build pipelines. Currently keys or credentials must be provided to the plugin to sign the metadata, whereas Sigstore offers keyless signing and verification. The addition of Sigstore transport will allow seamless uploading of metadata to Rekor transparency log. This project aims to enhance the Jenkins plugin by adding Sigstore support, allowing keyless signing and adding Sigstore transport. Expected Outcome: in-toto-jenkins plugins gets support for Sigstore
Help contributors get started with improving the documentation of CNCF projects and TAGs. To start, we'd like mentees to help to improve both the documentation of a project, and also encourage them to contribute to other projects. So, view the issues as a starting point to help start your career in open source. Expected Outcome: Develop effective documentation for CNCF projects. As a start, the CNCF project in-toto has a fairly clear set of requirements for what documentation changes are needed.