Skip to content

data: map publications to personas, problems, and project relationships - #42

Open
eddie-knight wants to merge 1 commit into
mainfrom
data/publication-mappings
Open

eddie-knight wants to merge 1 commit into
mainfrom
data/publication-mappings

Conversation

@eddie-knight

Copy link
Copy Markdown
Collaborator

Publications rendered persona/problem sections and relationship edges identically to projects since the 4P's reorg, but most of the data feeding those sections was missing.

This is not intended to get anything across the finish line, but fills some of the gaps:

  • needs-review produces/consumes/implements edges touching sbom, vex, osv-record, in-toto-attestation, and osps-baseline, authored on the declaring records (bomctl, protobom, sbomit, GUAC, Zarf, Minder, Package Analysis, OSV/OpenVEX)
  • curator-drafted persona and problem mappings for the six externally-owned specs in data/definitions/publications.yml
  • a derived 'Published by' list on /publications/security-insights/, built from each record's own insights: link rather than authored edges, so the fact stays stated in one place

Publications rendered persona/problem sections and relationship edges
identically to projects since the 4P's reorg, but most of the data feeding
those sections was missing. This fills the gaps:

- needs-review produces/consumes/implements edges touching sbom, vex,
  osv-record, in-toto-attestation, and osps-baseline, authored on the
  declaring records (bomctl, protobom, sbomit, GUAC, Zarf, Minder,
  Package Analysis, OSV/OpenVEX)
- curator-drafted persona and problem mappings for the six externally-owned
  specs in data/definitions/publications.yml
- a derived 'Published by' list on /publications/security-insights/, built
  from each record's own insights: link rather than authored edges, so the
  fact stays stated in one place

Signed-off-by: Eddie Knight <knight@linux.com>

@SecurityCRob SecurityCRob left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

good stuff! thank you!!!!!!!!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants