OSAR and the attestation feature design #66
Replies: 2 comments 2 replies
-
|
can we create second point JSON to "completionCriteria":{ |
Beta Was this translation helpful? Give feedback.
-
Process to trigger OSAR attestationThe process is designed to ensure a structured approach to conducting assessments through a series of predefined steps (playbooks). Upon completion of these steps, an attestation is triggered to certify the completion and accuracy of the assessments. Process Steps1. Creation of an Overarching Playbook:The analyst initiates the process by creating an overarching playbook. This playbook serves as a master guide that outlines the sequence of assessment steps to be executed. 2. Selection and Execution of Individual Playbooks:
3. Steps in the Overarching Playbook:Step 1: Execute the first selected playbook. 4. Attestation Command:The attestation is triggered through a specific command (besman command), designed to formalize the completion of the assessment process. 5. Documentation and Pull Request:Upon completion of the attestation, the analyst is responsible for documenting the executed playbooks and the attestation information. 6. Post-Execution InformationFollowing the completion of the playbooks and the attestation process, the project information within the BeSLighthouse dashboard will be updated to include details of the executed playbooks and the attestation information. 7. Additional Considerations
|
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Design discussion for attestation and verification of OSAR (Open Source Assessment Report)
"completionCriteria":[
{"sbom":true},
{"licenseCompliance":true},
{"criticalityScore":true},
{"scorecard":true},
{"sast":true}
],
"completionStatus":true
Beta Was this translation helpful? Give feedback.
All reactions