Egeria has a clear focus on ensuring the code delivered is of the highest quality to ensure that downstream consumers can leverage Egeria with as minimal risk as possible.
Specific items that Egeria employs include but are not limited to...
- Participation in the Core Infrastructure Initiative Best Practices Badge Program. This is a free program designed with the open source community with criteria that evolves to allow for compensating controls rather than a strict mechanical process.
- GitHub Actions to automatically build, test, and scan for vulnerabilities.
- GitHub Dependabot to automatically update dependencies.
- GitHub CodeQL to automatically scan for security vulnerabilities.
- SBOM (Software Bill of Materials) generated for every release in CycloneDX format (JSON and XML).
- GitHub Security Advisories for triaging security issues that come through (egeria-security@lists.lfaidata.foundation) and other confidential channels before publishing them for broader community awareness.
For more questions on Egeria's commitment to code quality, feel free to reach out to the Egeria development team
If you would like to report a security vulnerability, please do so via the Egeria development team.
License: CC BY 4.0, Copyright Contributors to the ODPi Egeria project.