Skip to content

Full scanning aware validated software releases #512

Description

@fgeorgatos

The challenge here shall be (gitlab-ci only for now, but ready to reuse as needed) to:

  • Setup an ORT GitLab Pipeline
  • Select, Use and Demo at least 5 plugins from https://oss-review-toolkit.org/ort/docs/category/plugins
  • Provide the template workflow to arrive from source tree to full scanning aware validated software releases that are pip available (this is conditional on all previous challenges having been met by other contributors, you've been warned)
  • Gate on coverage thresholds and linting checks explicitly, preferably via the makefile
  • Require passing full test matrix (multiple Python versions, OSes) before a release job can trigger
  • Pin build dependencies in CI to avoid supply-chain drift during the build itself (if there is any left!)
  • apply bandit, fix what is visible (or document it, if is not timely)
  • document sbom products
  • show how to Sign releases with Sigstore (cosign / sigstore-python) - usable but ready to comment out before merging step
  • demo in live mode the process end-to-end in a Github codespace context live session

PoH & contributing.md compliance mandatory, at all times. no force pushing.

Prep for other modernisation efforts:

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions