Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update index.md #1413

Merged
merged 5 commits into from
Nov 4, 2023
Merged

Update index.md #1413

merged 5 commits into from
Nov 4, 2023

Conversation

eryn-muetzel
Copy link
Contributor

Updated copy and added new logo. Please merge after review

Copy link
Member

@rdimitrov rdimitrov left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I rebased your PR due to a conflict with main and added a few comments 👍


Minder consists of a single golang binary which requires a backing Postgres database. For more details on the architecture, see the [System Architecture](./developer_guide/architecture) section.
* **Repo configuration and security:** Simplify configuration and management of security settings and policies across repos.
* **Proactive security enforcement:** Continuously enforce best practice security configurations by setting granular policies to alert or auto-remediate.
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same as above.

Minder is currently in early development.
Experimental stage

The public roadmap for Minder is available here: [link]
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I guess the missing link was intentional until we have it, but just pointing in case it's an error.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, intentional until we have it

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The missing link is causing our docs CI to fail. Now that we merged the roadmap we can put the link there I think.

* **Repo configuration and security:** Simplify configuration and management of security settings and policies across repos.
* **Proactive security enforcement:** Continuously enforce best practice security configurations by setting granular policies to alert or auto-remediate.
* **Artifact attestation:** Continuously verify that packages are signed to ensure they’re tamper-proof, using the open source project Sigstore.
* **Dependency and license management:** Manage dependency security posture by helping developers make better choices and enforcing controls. Minder is integrated with [Trusty by Stacklok](http://trustypkg.dev) to enable policy-driven dependency management based on the risk level of dependencies.
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think we don't have license management (yet).

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You're correct - I am setting up the categories that shouldn't change too much based on roadmap. We can remove "and license management" if you think that is better

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey, I've decided to go ahead and implement something in that licensing direction - #1419. It's rather simple but I think it should add enough value 👍

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Awesome, thanks for doing that!

Minder unifies the security of your software supply chain by providing a single
place to manage your security profiles and a central location to view and remediate
the results.
Minder allows users to enroll repositories and define policy to ensure repositories and artifacts are configured consistently and securely. Policies can be set to alert or autoremediate. Minder provides a predefined set of rules and can also be configured to apply custom rules.
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Currently alerts can be enabled independently of the remediate feature (it's not one vs the other)

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good point - I can update

Updated based on comments
dussab
dussab previously approved these changes Nov 3, 2023
Signed-off-by: Radoslav Dimitrov <radoslav@stacklok.com>
Copy link
Member

@rdimitrov rdimitrov left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@eryn-muetzel - FYI added the link to the roadmap and also removed the html resizing since it was causing the docs build to fail 👍

@JAORMX JAORMX merged commit 9eff72e into mindersec:main Nov 4, 2023
2 checks passed
@JAORMX JAORMX deleted the patch-1 branch November 4, 2023 08:23
@evankanderson evankanderson mentioned this pull request Nov 6, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants