This document captures technologies that are hosted in OpenSSF and some technologies in CNCF. The technical stack in this document demonstrates how OSS security technologies make software supply chain more secure through dependency management.
The goals of this document are:
- To help open source software producers discover, adopt as appropriate, and contribute to technical initiatives of OpenSSF (and related foundations) to improve security.
- To provide an easy model for our end user organizations large and small to have a framework/reference architecture to help them consider adopting OpenSSF technical projects and guidance.
This document is based on the previous work conducted in OpenSSF BEST Working Group: