From: Stewart Smith <stewart@linux.vnet.ibm.com>
To: "Tanous\, Ed" <ed.tanous@intel.com>,
Brad Bishop <bradleyb@fuzziesquirrel.com>,
OpenBMC Maillist <openbmc@lists.ozlabs.org>
Subject: RE: OpenBMC community telecon - 11/20 Agenda
Date: Tue, 21 Nov 2017 11:27:33 +1100 [thread overview]
Message-ID: <873758zdai.fsf@linux.vnet.ibm.com> (raw)
In-Reply-To: <7E9441B1E5EFFD4681F54958E82169932F4A58B2@ORSMSX114.amr.corp.intel.com>
"Tanous, Ed" <ed.tanous@intel.com> writes:
> Secure coding guidelines:
> What secure coding guidelines are other groups/individuals using? I'd like to have an open discussion about how to move toward more secure coding guidelines with the minimum possible interruption while alienating the minimum number of people. Some subtopics:
> 1. Can anything be enforced at the master branch?
> 2. Can anything be enforced by policy? (example: reference components must be secure)
> 3. Does anyone have experience with automating secure coding
> guidelines?
A minimal starting point would be to run every code repository through
Coverity Scan. Setting this up with travs-ci isn't too hard (we do it
for parts of host firmware today).
Efforts to limit the damage could also be good, like strict SELinux
policy. After all, much of the current design would work quite well for
that.
--
Stewart Smith
OPAL Architect, IBM.
next prev parent reply other threads:[~2017-11-21 0:27 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2017-11-20 19:26 OpenBMC community telecon - 11/20 Agenda Brad Bishop
2017-11-20 19:57 ` Tanous, Ed
2017-11-21 0:27 ` Stewart Smith [this message]
2017-11-21 1:04 ` Tanous, Ed
2017-11-21 2:40 ` Andrew Jeffery
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=873758zdai.fsf@linux.vnet.ibm.com \
--to=stewart@linux.vnet.ibm.com \
--cc=bradleyb@fuzziesquirrel.com \
--cc=ed.tanous@intel.com \
--cc=openbmc@lists.ozlabs.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.