Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Interested in Dev/Contributing to GUAC? #1

Closed
lumjjb opened this issue Aug 3, 2022 · 58 comments
Closed

Interested in Dev/Contributing to GUAC? #1

lumjjb opened this issue Aug 3, 2022 · 58 comments

Comments

@lumjjb
Copy link
Contributor

lumjjb commented Aug 3, 2022

Welcome! This thread is on expressing interest in contributing to GUAC! We are glad to welcome our fellow open source contributors! As the project is starting up, we will be creating issues that folks can pick up and work on. In the meantime, as the code base is forming up, we'd like to engage directly with our contributors!

BTW we now have a slack channel: https://openssf.slack.com/archives/C03U677QD46

If you are interested in contributing, it would be very helpful to provide the following details (copy and paste into your comment):

1. I am interested in contributing to:
- [ ] Development
- [ ] Documentation
- [ ] Issue triage and community
- [ ] Technical advisory (review [governance document](https://github.com/artifact-ff/artifact-ff/blob/main/GOVERNANCE.md#technical-advisory-members))

2. I am here because:
- [ ] Personal interest
- [ ] My company/orgs i work with are interested in this

3. What is your associated company/org if you're contributing in their capacity? _________

4. Depending on how things go, I may be interested in becoming a maintainer of the project
- [ ] Yes

5. (optional) I have expertise in:
- [ ] Neo4j
- [ ] Cypher
- [ ] GraphQL
- [ ] Intoto
- [ ] SPDX
- [ ] CycloneDX
- [ ] Others (fill in):
@cpendery
Copy link
Collaborator

cpendery commented Aug 4, 2022

  1. I am interested in contributing to:
  • Development
  • Documentation
  • Issue triage and community
  • Technical advisory (review governance document)
  1. I am here because:
  • Personal interest
  • My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity?

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • Yes
  1. (optional) I have expertise in:
  • Neo4j
  • Cypher
  • GraphQL
  • Intoto
  • SPDX
  • CycloneDX
  • Others (fill in): Grype, Syft, Trivy, OSV data formats, Golang

Note: my company may be interested in the project and me contributing in their capacity, so I'll update this note if they approve that work

@shafeeshafee
Copy link
Contributor

shafeeshafee commented Aug 5, 2022

  1. I am interested in contributing to:
  • Development
  • Documentation
  • Issue triage and community
  • Technical advisory (review governance document)
  1. I am here because:
  • Personal interest
  • My company/orgs I work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? _________

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • Yes
  • Maybe. Would be interested to stick with it so I can learn more about supply chain security 😃
  1. (optional) I have expertise in:
  • Neo4j
  • Cypher
  • GraphQL (somewhat)
  • Intoto
  • SPDX
  • CycloneDX
  • Others (fill in): HTML, CSS, JavaScript, Node.js, React, SQL. Open to expand my contribution/learning if more work is needed in any area of this project

@Jhooomn
Copy link

Jhooomn commented Aug 5, 2022

  1. I am interested in contributing to:
  • Development
  • Documentation
  • Issue triage and community
  • Technical advisory (review governance document)
  1. I am here because:
  • Personal interest
  • My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? _________

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • Yes
  1. (optional) I have expertise in:
  • Neo4j
  • Cypher
  • GraphQL
  • Intoto
  • SPDX
  • CycloneDX
  • Others (java, spring boot, mySql, mongodb, redis, golang, xml, json, rabbitmq, activemq, gcp):

@lumjjb lumjjb changed the title Interested in Dev/Contributing to AFF? Interested in Dev/Contributing to GUAC? Aug 17, 2022
@nadgowdas
Copy link
Contributor

nadgowdas commented Aug 17, 2022

  1. I am interested in contributing to:
  • Development
  • Documentation
  • Issue triage and community
  • Technical advisory (review governance document)
  1. I am here because:
  • Personal interest
  • My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? _Intel

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • Yes
  1. (optional) I have expertise in:
  • Neo4j
  • Cypher
  • GraphQL
  • Intoto
  • SPDX
  • CycloneDX
  • Others (fill in):

@lumjjb
Copy link
Contributor Author

lumjjb commented Aug 19, 2022

btw we have a slack channel now! https://openssf.slack.com/archives/C03U677QD46 come join

@halcyondude
Copy link

halcyondude commented Aug 19, 2022

  1. I am interested in contributing to:
  • Development
  • Documentation
  • Issue triage and community
  • Technical advisory (review governance document)
  1. I am here because:
  • Personal interest
  • My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? ...stay tuned.

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • Yes
  1. (optional) I have expertise in:
  • Neo4j
  • Cypher
  • GraphQL
  • Intoto
  • SPDX
  • CycloneDX
  • Others (fill in):
    • cncf/landscape-graph
    • cncf/tag-observability
    • k8s, linkerd, operators, streaming, ci, gitops, dataThings, STRIDE, pride, compliance, ...
    • Cirrus, Nimbostratus, Cumulonimbus, Stratocumulus, Mammatus, Orographic, Lenticular, and Contrails.

@lumjjb lumjjb pinned this issue Aug 22, 2022
@pxp928 pxp928 unpinned this issue Aug 30, 2022
@pxp928 pxp928 pinned this issue Aug 30, 2022
@desenna
Copy link
Contributor

desenna commented Sep 30, 2022

  1. I am interested in contributing to:
  • Development
  • Documentation
  • Issue triage and community
  • Technical advisory (review governance document)
  1. I am here because:
  • Personal interest
  • My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? _________

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • Yes
  1. (optional) I have expertise in:
  • Neo4j
  • Cypher
  • GraphQL
  • Intoto
  • SPDX
  • CycloneDX
  • Others (fill in): Grype, Syft, Trivy, testing, CI

Note: my company may be interested in the project and me contributing in their capacity, so I'll update this note if they approve that work.

@QAInsights
Copy link

  1. I am interested in contributing to:
  • Development
  • Documentation
  • Issue triage and community
  • Technical advisory (review governance document)
  1. I am here because:
  • Personal interest
  • My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? _________

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • Yes
  1. (optional) I have expertise in:
  • Neo4j
  • Cypher
  • GraphQL
  • Intoto
  • SPDX
  • CycloneDX
  • Others (fill in):

@JudeSafo
Copy link

  1. I am interested in contributing to:
  • Development
  • Documentation
  • Issue triage and community
  • Technical advisory (review governance document)
  1. I am here because:
  • Personal interest
  • My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? https://haiphen.io__

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • Yes
  1. (optional) I have expertise in:
  • Neo4j
  • Cypher
  • GraphQL
  • Intoto
  • SPDX
  • CycloneDX
  • Others (fill in): ml, nlp, BERT, inductive GNN

@danielhaim1
Copy link

danielhaim1 commented Oct 22, 2022

  1. I am interested in contributing to:
  • Development
  • Documentation
  • Issue triage and community
  • Technical advisory (review governance document)
  1. I am here because:
  • Personal interest
  • My company/orgs i work with are interested in this
  1. Depending on how things go, I may be interested in becoming a maintainer of the project
  • Yes
  1. (optional) I have expertise in:
  • Neo4j
  • Cypher
  • GraphQL
  • Intoto
  • SPDX
  • CycloneDX
  • Others (fill in):

@scpli3
Copy link

scpli3 commented Oct 22, 2022

  1. I am interested in contributing to:
  • Development
  • Documentation
  • Issue triage and community
  • Technical advisory (review governance document)
  1. I am here because:
  • Personal interest
  • My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? _________

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • Yes
  1. (optional) I have expertise in:
  • Neo4j
  • Cypher
  • GraphQL
  • Intoto
  • SPDX
  • CycloneDX
  • Others (fill in):

@codelion
Copy link

codelion commented Oct 23, 2022

  1. I am interested in contributing to:
  • Development
  • Documentation
  • Issue triage and community
  • Technical advisory (review governance document)
  1. I am here because:
  • Personal interest
  • My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? N/A

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • Yes
  1. (optional) I have expertise in:
  • Neo4j
  • Cypher
  • GraphQL
  • Intoto
  • SPDX
  • CycloneDX
  • Others (fill in):
    We designed and implemented a similar Security Graph Language (SGL) @sourceclear.
    The work was presented at IEEE SecDev 2018:
    SGL Slides
    SGL Paper

@anthonyharrison
Copy link

anthonyharrison commented Oct 23, 2022

  1. I am interested in contributing to:
  • Development
  • Documentation
  • Issue triage and community
  • Technical advisory (review governance document)
  1. I am here because:
  • Personal interest
  • My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? _________

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • Yes
  1. (optional) I have expertise in:
  • Neo4j
  • Cypher
  • GraphQL
  • Intoto
  • SPDX
  • CycloneDX
  • Others (fill in): Python

@sallienewton
Copy link

  1. I am interested in contributing to:
  • Development
  • [x ] Documentation
  • [x ] Issue triage and community
  • [x ] Technical advisory (review governance document)
  1. I am here because:
  • [x ] Personal interest
  • [x ] My company/orgs I work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? Intel_______

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • [x ] Yes
  • [x ] Co-Maintainer
  1. (optional) I have expertise in:
  • Neo4j
  • Cypher
  • GraphQL
  • Intoto
  • SPDX
  • CycloneDX
  • [x ] Others (fill in):
  • [x ] Policy
  • [x ] Policy Shifted Left
  • [x ] SDLC Requirements
  • [x ] Risk Management
  • [x ] Compliance through SDLC
  • [x ] NIST 800-218
  • [x ] Smart aggregation turning data into meaning

@GreyXor
Copy link

GreyXor commented Oct 24, 2022

  1. I am interested in contributing to:
  • Development
  • Documentation
  • Issue triage and community
  • Technical advisory (review governance document)
  1. I am here because:
  • Personal interest
  • My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity?
    Morphysm

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • Yes
  1. (optional) I have expertise in:
  • Neo4j
  • Cypher
  • GraphQL
  • Intoto
  • SPDX
  • CycloneDX
  • Go
  • CodeQL

@cepix1234
Copy link

  1. I am interested in contributing to:
  • Development
  • Documentation
  • Issue triage and community
  • Technical advisory (review governance document)
  1. I am here because:
  • Personal interest
  • My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? _________

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • Yes
  1. (optional) I have expertise in:
  • Neo4j
  • Cypher
  • GraphQL
  • Intoto
  • SPDX
  • CycloneDX
  • Others (fill in): Python, C#, C++, HTML, PHP, MSSQL, Oracle, TypeScript, NodeJs, Bash, Batch, PowerShell

@rvema
Copy link

rvema commented Oct 24, 2022

  1. I am interested in contributing to:
  • Development
  • Documentation
  • Issue triage and community
  • Technical advisory (review governance document)
  1. I am here because:
  • Personal interest
  • My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? FannieMae

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • Yes
  1. (optional) I have expertise in:
  • Neo4j
  • Cypher
  • GraphQL
  • Intoto
  • SPDX
  • CycloneDX
  • Others (fill in): Java, TypeScript, Python, Bash

@ran-dall
Copy link

  1. I am interested in contributing to:
  • Development
  • Documentation
  • Issue triage and community
  • Technical advisory (review governance document)
  1. I am here because:
  • Personal interest
  • My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? _________

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • Yes
  1. (optional) I have expertise in:
  • Neo4j
  • Cypher
  • GraphQL
  • Intoto
  • SPDX
  • CycloneDX
  • Others (fill in): Go, Rust, C/C++, JS, TS, Ruby, Bash, Python, WASM, HTML/CSS, SQL

@nettrino
Copy link

nettrino commented Oct 26, 2022

  1. I am interested in contributing to:
  • Development
  • Documentation
  • Issue triage and community
  • Technical advisory (review governance document)
  1. I am here because:
  • Personal interest
  • My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? Crash Override

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • Yes
  1. (optional) I have expertise in:
  • Neo4j (familiarity)
  • Cypher (familiarity)
  • GraphQL (familiarity)
  • Intoto
  • SPDX
  • CycloneDX (familiarity)
  • Others (fill in): Python, Golang, C, LLVM, GCC, JS, TS, Bash, Python, HTML/CSS, SQL

@trmiller trmiller unpinned this issue Oct 26, 2022
@trmiller trmiller pinned this issue Oct 26, 2022
@mraipsec-mra
Copy link

mraipsec-mra commented Oct 27, 2022

  1. I am interested in contributing to:
  • Development
  • Documentation
  • Issue triage and community
  • Technical advisory (review governance document)
  1. I am here because:
  • Personal interest
  • My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? _NA

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • Yes
  1. (optional) I have expertise in:
  • Neo4j
  • Cypher
  • GraphQL
  • Intoto
  • SPDX
  • CycloneDX
  • Developer Advocacy
  • Platform Enabler
  • Programming Distributed Systems & Design Internals
  • Best practices, recommendations for cloud native applications for good.

@justinabrahms
Copy link

  1. I am interested in contributing to:
  • Development
  • Documentation
  • Issue triage and community
  • Technical advisory (review governance document)
  1. I am here because:
  • Personal interest
  • My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? eBay

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • Yes
  1. (optional) I have expertise in:
  • Neo4j
  • Cypher
  • GraphQL
  • Intoto
  • SPDX
  • CycloneDX
  • Others (fill in):

@JonZeolla
Copy link
Contributor

JonZeolla commented Oct 27, 2022

  1. I am interested in contributing to:
  • Development
  • Documentation
  • Issue triage and community
  • Technical advisory (review governance document)
  1. I am here because:
  • Personal interest
  • My company/orgs I work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? Seiso - cloud native security consulting. https:/sei.so

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • Yes
  1. (optional) I have expertise in:
  • Neo4j
  • Cypher
  • GraphQL
  • Intoto (user)
  • SPDX
  • CycloneDX
  • Others (fill in): Policy [as code], compliance automation, TAG-Security Controls, being pedantic

@tixu
Copy link

tixu commented Oct 31, 2022

  1. I am interested in contributing to:
  • [ x ] Development
  • [ x ] Documentation
  • [ ] Issue triage and community
  • Technical advisory (review governance document)
  1. I am here because:
  • [ X ] Personal interest
  • My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? _________

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • Yes
  1. (optional) I have expertise in:
  • [ X ] Neo4j
  • Cypher
  • GraphQL
  • Intoto
  • SPDX
  • [ X ] CycloneDX
  • Others (fill in):

@raj-andy1
Copy link

  1. I am interested in contributing to:
  • Development
  • [X ] Documentation
  • [ X] Issue triage and community
  • [ X] Technical advisory (review governance document)
  1. I am here because:
  • [ X] Personal interest
  • My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? _________

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • [X ] Yes
  1. (optional) I have expertise in:
  • Neo4j
  • Cypher
  • GraphQL
  • Intoto
  • SPDX
  • CycloneDX
  • [X ] Others (fill in): Python, Compliance, FedRAMP,

@ryancraig
Copy link

  1. I am interested in contributing to:
  • Development
  • Documentation
  • Issue triage and community
  • Technical advisory (review governance document)
  1. I am here because:
  • Personal interest
  • My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? _________

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • Yes
  1. (optional) I have expertise in:
  • Neo4j
  • Cypher
  • GraphQL
  • Intoto
  • SPDX
  • CycloneDX
  • Others (fill in): SLSA Framework, CUElang

@Jhooomn
Copy link

Jhooomn commented Nov 15, 2022

btw we have a slack channel now! https://openssf.slack.com/archives/C03U677QD46 come join

could you please share another link ? I´m not able to join to this channel :(

@robh-snyk
Copy link
Collaborator

robh-snyk commented Nov 22, 2022

  1. I am interested in contributing to:
  • Development
  • Documentation
  • Issue triage and community
  • Technical advisory (review governance document)
  1. I am here because:
  • Personal interest
  • My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity?

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • Yes
  1. (optional) I have expertise in:
  • Neo4j
  • Cypher
  • GraphQL
  • Intoto
  • SPDX
  • CycloneDX
  • Others (fill in):

@KumarAbhishekShahi
Copy link

KumarAbhishekShahi commented Nov 23, 2022

  1. I am interested in contributing to:
  • Development
  • Documentation
  • Issue triage and community
  • Technical advisory (review governance document)
  1. I am here because:
  • Personal interest
  • My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? Not Applicable_____

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • Yes
  1. (optional) I have expertise in:
  • Neo4j
  • Cypher
  • GraphQL
  • Intoto
  • SPDX
  • CycloneDX
  • Others (fill in):

@gth999
Copy link

gth999 commented Nov 27, 2022

  1. I am interested in contributing to:
  • Development
  • Documentation
  • Issue triage and community
  • Technical advisory (review governance document)
  1. I am here because:
  • Personal interest
  • My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? Not Applicable

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • Yes
  1. (optional) I have expertise in:
  • Neo4j
  • Cypher
  • GraphQL
  • Intoto
  • SPDX
  • CycloneDX
  • Others (fill in):

@lumjjb
Copy link
Contributor Author

lumjjb commented Dec 7, 2022

Hi All! We are having our first community meeting next week! Looking forward to meeting everyone!!

https://calendar.google.com/calendar/event?action=TEMPLATE&tmeid=MWc4aDR2cG80dXIyMmRkM[…]7576484474ebefce57c47d1eaeb02d6%40group.calendar.google.com

Google Meet link: meet.google.com/zpf-pfkj-ywd

@cpendery @shafeeshafee @Jhooomn @nadgowdas @halcyondude @desenna @QAInsights @JudeSafo @danielhaim1 @scpli3 @codelion @anthonyharrison @sallienewton @GreyXor @cepix1234 @rvema @ran-dall @nettrino @ralav @justinabrahms @JonZeolla @tixu @raj-andy1 @zprobst @raj-riskone @apmarshall @rjain15 @s-spindler @peter-thomas-db @AndrzejRPiotrowski @ajvpot @Siddhant-K-code @ryancraig @robh-snyk @KumarAbhishekShahi @gth999

@JudeSafo
Copy link

JudeSafo commented Dec 7, 2022 via email

@rossmcewan
Copy link

  1. I am interested in contributing to:
  • Development
  • Documentation
  • Issue triage and community
  • Technical advisory (review governance document)
  1. I am here because:
  • Personal interest
  • My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? _________

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • Yes
  1. (optional) I have expertise in:
  • Neo4j
  • Cypher
  • GraphQL
  • Intoto
  • SPDX
  • CycloneDX
  • Others (fill in):

@mihaimaruseac
Copy link
Collaborator

mihaimaruseac commented Dec 7, 2022

What date and time? FYI: Unable to join the slack channel thus far.

Monday, 12th of December, 8 am Pacific Time, 11 am East Coast time

@JudeSafo
Copy link

JudeSafo commented Dec 12, 2022 via email

@rewanthtammana
Copy link
Contributor

  1. I am interested in contributing to:
  • Development
  • Documentation
  • Issue triage and community
  • Technical advisory (review governance document)
  1. I am here because:
  • Personal interest
  • My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? Freelancer

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • Yes
  1. (optional) I have expertise in:

Blog - https://blog.rewanthtammana.com/
Portfolio - https://rewanthtammana.com/

@lumjjb
Copy link
Contributor Author

lumjjb commented Dec 12, 2022

@JudeSafo here's the meet link: meet.google.com/zpf-pfkj-ywd

@developer-guy
Copy link

  1. I am interested in contributing to:
  • Development
  • Documentation
  • Issue triage and community
  • Technical advisory (review governance document)
  1. I am here because:
  • Personal interest
  • My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? Trendyol

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • Yes
  1. (optional) I have expertise in:
  • Neo4j
  • Cypher
  • GraphQL
  • Intoto
  • SPDX
  • CycloneDX
  • Others (fill in): Golang, Sigstore, SBOM, Tekton, Tekton Chains, SPIFFE, cosign, ko, Docker Buildx, Buildpacks, Kyverno, Flux, Helm, regclient, zot, OCI, Vault

@Dentrax
Copy link

Dentrax commented Dec 13, 2022

  1. I am interested in contributing to:
  • Development
  • Documentation
  • Issue triage and community
  • Technical advisory (review governance document)
  1. I am here because:
  • Personal interest
  • My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? Trendyol

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • Yes
  1. (optional) I have expertise in:
  • Neo4j
  • Cypher
  • GraphQL
  • Intoto
  • SPDX
  • CycloneDX
  • Others (fill in): golang, sigstore, oci, sbom, slsa, and many more

@lumjjb
Copy link
Contributor Author

lumjjb commented Dec 13, 2022

Recording from the inaugural GUAC community meeting on 12 Dec (https://drive.google.com/file/d/1u1O6RSYeZT2w6u9jxeSj9X9Z1uqtD1Vn/view)

@hkadakia
Copy link

hkadakia commented Dec 20, 2022

  1. I am interested in contributing to:
  • Development
  • Documentation
  • Issue triage and community
  • Technical advisory (review governance document)
  1. I am here because:
  • Personal interest
  • My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? Yahoo

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • Yes
  1. (optional) I have expertise in:
  • Neo4j
  • Cypher
  • GraphQL
  • Intoto
  • SPDX
  • CycloneDX
  • Others (fill in): golang, sbom, syft

@hosseinsia
Copy link

hosseinsia commented Dec 22, 2022

  1. I am interested in contributing to:
  • Development
  • Documentation
  • Issue triage and community
  • Technical advisory (review governance document)
  1. I am here because:
  • Personal interest
  • My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? _________

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • Yes
  1. (optional) I have expertise in:
  • Neo4j
  • Cypher
  • GraphQL
  • Intoto
  • SPDX
  • CycloneDX
  • Others (fill in): SBOM

@alftom
Copy link

alftom commented Jan 5, 2023

The distributed energy grid might be able to use this so I'd like to get involved. Two questions:

  • do I need to be a member of OpenSSF to join the Slack channel?
  • what/who is going to host the database that stores all this data?
  1. I am interested in contributing to:
  • Development
  • Documentation
  • Issue triage and community
  • Technical advisory (review governance document)
  1. I am here because:
  • Personal interest
  • My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? Lumian.org and SunSpec.org

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • Yes
  1. (optional) I have expertise in:
  • Neo4j
  • Cypher
  • GraphQL
  • Intoto
  • SPDX
  • CycloneDX
  • [x ] Others (fill in): distributed energy, Web3, smart contracts, solidity,

@lumjjb
Copy link
Contributor Author

lumjjb commented Feb 2, 2023

Hi fellow GUAC community members!

We have some exciting updates and announcements for the GUAC project!

Community Updates!

GUAC Beta v0.1

  • We have a GUAC Beta v0.1 planned coming up. Besides a deployable services, this also marks a milestone in the development of a GraphQL which will eventually mature to the v1.0 API. The GUAC Beta is planned for end of March.
  • We had the first maintainer summit since the initial formation of the project. The focus of the workshop was to discuss and get consensus on the open issues/design docs, as well as get some clarity around the proposed GUAC Beta v0.1. The summit notes are made available here (located under Additional References in README).

Lots of changes coming! Including some breaking ones!

  • During this transition to the new API, there will be a LOT of code refactors and breaking changes within the next 3 months of project development.
  • To ensure that folks can still try out the initial POC, we have created a tag for v0.0.1 to pin to the demo.
  • We understand that this will impact contributors that want to contribute code to the project, since there are many moving pieces during this time, there is a chance that certain files within will be refactored or deprecated. For those wanting to contribute, we encourage discussing with a maintainer through issues or slack about the topic first before picking up an issue or opening a PR!

Cheers
GUAC Maintainers

@lumjjb
Copy link
Contributor Author

lumjjb commented Feb 8, 2023

@alftom

do I need to be a member of OpenSSF to join the Slack channel?

no, anyone can join it.

what/who is going to host the database that stores all this data?

for the attestations and the blob themselves this would be from the repo/storage that they reside in. For the graph DB, currently, we store the linkage and metadata in neo4j. However, this backend is extensible.

In terms of document storage, we have chatted about potentially have a collector that handles this for you (e.g. if you point it to a http endpoint, it will keep a copy of the documents it collects), and these are exposed through the SourceInformation field within the nodes/edges.

Would you mind creating a separate issue if you'd like further expansion so it will be better searchable! Thanks!

@dejanb
Copy link
Contributor

dejanb commented Feb 13, 2023

  1. I am interested in contributing to:
  • Development
  • Documentation
  • Issue triage and community
  • Technical advisory (review governance document)
  1. I am here because:
  • Personal interest
  • My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? Red Hat

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • Yes
  1. (optional) I have expertise in:
  • Neo4j
  • Cypher
  • GraphQL
  • Intoto
  • SPDX
  • CycloneDX
  • Others (fill in): Rust, Kubernetes, Containers, Java, Community building

@kanchan-dhamane
Copy link
Contributor

  1. I am interested in contributing to:
  • Development
  • Documentation
  • Issue triage and community
  • Technical advisory (review governance document)
  1. I am here because:
  • Personal interest
  • My company/orgs i work with are interested in this
  1. What is your associated company/org if you're contributing in their capacity? _________

  2. Depending on how things go, I may be interested in becoming a maintainer of the project

  • Yes
  1. (optional) I have expertise in:
  • Neo4j
  • Cypher
  • GraphQL
  • Intoto
  • SPDX
  • CycloneDX
  • Others (golang):

@pxp928
Copy link
Collaborator

pxp928 commented Mar 10, 2023

Hello everyone! Please join our slack channel: https://openssf.slack.com/archives/C03U677QD46. If you are interested or looking to contribute and can't find an issue to work on, please reach out to us and we will be happy to point you to issues that need tackling!

@lumjjb
Copy link
Contributor Author

lumjjb commented Apr 28, 2023

Hi all! Now that we are close to our GUAC v0.1 beta launch (in a few weeks). Part of that is closing this issue! And pointing everyone over to the new contributing page that we've updated and fleshed out! So please do take a look there!

We have additional information on how to contribute and also a contributor ladder as well!

@lumjjb lumjjb closed this as completed Apr 28, 2023
@mihaimaruseac mihaimaruseac unpinned this issue Apr 28, 2023
mrizzi pushed a commit to mrizzi/guac that referenced this issue Jun 23, 2023
mrizzi added a commit to mrizzi/guac that referenced this issue Nov 10, 2023
mrizzi added a commit to mrizzi/guac that referenced this issue Nov 14, 2023
* Ent - PackageVersion: added index for improving IsDependency ingestion (guacsec#1439)

Signed-off-by: mrizzi <[email protected]>

* Ent: Package,IsDependency concurrent bulk ingestions (guacsec#1440)

Signed-off-by: mrizzi <[email protected]>

* Ent - HasMetadata: fix ingesting same twice (guacsec#1392)

Signed-off-by: mrizzi <[email protected]>

* Ent - Vulnerability endpoints: applied concurrent approach

Signed-off-by: mrizzi <[email protected]>

* Ent implementation for use case guacsec#1-guacsec#2

Signed-off-by: mrizzi <[email protected]>

---------

Signed-off-by: mrizzi <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests