diff --git a/CNCF-Fossa.md b/CNCF-Fossa.md new file mode 100644 index 0000000..c0cf758 --- /dev/null +++ b/CNCF-Fossa.md @@ -0,0 +1,31 @@ +Work in Progress to record using CNCF Fossa to fulfil our license scanning requirement for onboarding + +- Request from @jeefy in CNCF access to Fossa for Confidential Containers +- Accept invite to https://app.fossa.com/projects + +## Setup connection between Fossa and Github Organisation + +- [Integrating FOSSA with GitHub instructions](https://docs.fossa.com/docs/github) +- Add Projects + +FossaAddProject + + +- Quick Import from Github + +From https://github.com/organizations/confidential-containers/settings/oauth_application_policy +- Connect with Service (Choosing Proceed without linking) +Screenshot 2022-04-27 at 16 25 48 + +- Ensure Fossa is an approved third party application for confidential containers + +Fossa View + +Screenshot 2022-04-27 at 22 02 14 + +Github View + +Screenshot 2022-04-27 at 22 02 24 + +- Finally Authorise Fossa using your Github Account (??Should we eventually setup a service account for this??) +