The supply-chain work is done
When we last wrote, in May, about half of the OpenSecOps components had been moved onto the new signed-release setup. The rest followed a week later, and since then it has all simply been running in the background. Nobody has had to change how they deploy.
We have now written up the whole thing in one place: why we did it, what it means for you, and the short list of what is still left. Read it here:
- Blog: OpenSecOps Supply Chain: Conversion Complete
- Same text on GitHub, if you want to comment: Discussion #28
If a security reviewer asks you about OpenSecOps, point them at the Trust page.
What to do
Nothing new. Pull the Installer, run ./init for Foundation and SOAR, then ./deploy-all as usual.
Peter Bengtson
OpenSecOps
Don't miss what's next. Subscribe to OpenSecOps Newsletter: