Re: Jenkins SDLC Security: LFX Security/Snyk adoption status updates

2021-05-10 Thread Oleg Nenashev
FTR we created the new *#lfx-security-2-pilot-with-snyk* channel in the CDF Slack workspace so that all sides can sync-up in a chat if needed. You can join the workspace by following the guidelines in https://www.jenkins.io/chat/#continuous-delivery-foundation All interested contributors and

Re: Jenkins SDLC Security: LFX Security/Snyk adoption status updates

2021-05-05 Thread Oleg Nenashev
UPD: The Jenkins Governance meeting approved official participation in the Pilot project. Approved by: Ulli Hafner, Gavin Mogan, Ewelina Wilkosz, Daniel Beck, Baptiste Mathus, Mark Waite (+ Olivier I'd guess) Thanks everyone for the feedback! On Wednesday, May 5, 2021 at 7:28:36 PM UTC+2 Oleg

Re: Jenkins SDLC Security: LFX Security/Snyk adoption status updates

2021-05-05 Thread Oleg Nenashev
Hi all, Just a quick update, we will be setting up a shared Slack channel in the CDF workspace. Once it is ready, we can use it for conversations. Pending ticket to the CDF: https://github.com/cdfoundation/foundation/issues/330 BR, Oleg On Tuesday, May 4, 2021 at 9:30:06 AM UTC+2 Oleg

Re: Jenkins SDLC Security: LFX Security/Snyk adoption status updates

2021-05-04 Thread Oleg Nenashev
Hi Olivier, For experiments, it might make sense to register Jenkins Infrastructure as the second organization. I do not anticipate major overlap between configs taking different technology stacks. Once Snyk adds support for multiple GitHub orgs, we can explore our options. M wrote: > Hi Oleg, >

Re: Jenkins SDLC Security: LFX Security/Snyk adoption status updates

2021-05-04 Thread 'Olblak' via Jenkins Developers
Hi Oleg, Thanks for driving this. Once we are allowed to have a second Github Organization, I would be very interested to experiment with it for the jenkins-infra organization. On Monday, 3 May 2021 at 22:24:44 UTC+2 Oleg Nenashev wrote: > Thanks for the interest Daniel! > > >> Would you like

Re: Jenkins SDLC Security: LFX Security/Snyk adoption status updates

2021-05-04 Thread Daniel Beck
On Mon, May 3, 2021 at 10:24 PM Oleg Nenashev wrote: > >> Would you like to participate as a contributor? > > What does this entail? > > That's a good question, to be seen. As a part of the pilot project we will > need: > >- Try out LFX Security 2.0 and configure it for some of our projects

Re: Jenkins SDLC Security: LFX Security/Snyk adoption status updates

2021-05-03 Thread Oleg Nenashev
Thanks for the interest Daniel! >> Would you like to participate as a contributor? > What does this entail? That's a good question, to be seen. As a part of the pilot project we will need: - Try out LFX Security 2.0 and configure it for some of our projects - Explore options for

Re: Jenkins SDLC Security: LFX Security/Snyk adoption status updates

2021-05-03 Thread Daniel Beck
Thanks again for driving this, Oleg! > On 3. May 2021, at 19:14, Oleg Nenashev wrote: > > The proposal is to start the pilot from a small list of the repositories > controlled by the pilot project participants: Jenkins core, its libraries, > and some plugins from maintainers who are