<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>TrustedOSS on OpenChain KWG</title><link>https://OpenChain-Project.github.io/OpenChain-KWG/tags/trustedoss/</link><description>Recent content in TrustedOSS on OpenChain KWG</description><generator>Hugo</generator><language>ko</language><atom:link href="https://OpenChain-Project.github.io/OpenChain-KWG/tags/trustedoss/index.xml" rel="self" type="application/rss+xml"/><item><title>TrustedOSS</title><link>https://OpenChain-Project.github.io/OpenChain-KWG/guide/trustedoss/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://OpenChain-Project.github.io/OpenChain-KWG/guide/trustedoss/</guid><description>&lt;div class="pageinfo pageinfo-primary"&gt;&#10;&lt;p&gt;TrustedOSS는 KWG 커뮤니티 활동에서 출발한 프로젝트로, 이 가이드의 저자가 공개했습니다.&#10;문서는 CC BY 4.0, 코드는 MIT와 Apache 2.0으로 배포합니다.&lt;/p&gt;&#10;&lt;p&gt;&lt;strong&gt;사이트: &lt;a href="https://trustedoss.github.io/"&gt;https://trustedoss.github.io/&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&#10;&#10;&lt;/div&gt;&#10;&#10;&lt;p&gt;TrustedOSS는 다음 네 가지를 다룹니다.&lt;/p&gt;&#10;&lt;h2 id="자체-인증-산출물-생성"&gt;자체 인증 산출물 생성&lt;/h2&gt;&#10;&lt;p&gt;ISO/IEC 5230과 ISO/IEC 18974 자체 인증에 필요한 문서를 AI 에이전트와 대화하며 만듭니다.&#10;조직 구성, 정책, 프로세스, SBOM 분석, 취약점 리포트, 교육 커리큘럼, 준수 선언문 초안까지&#10;단계별로 생성합니다. &lt;a href="https://OpenChain-Project.github.io/OpenChain-KWG/guide/opensource_for_enterprise/"&gt;기업 오픈소스 관리 가이드&lt;/a&gt;가 설명하는&#10;여섯 단계와 같은 순서를 따릅니다.&lt;/p&gt;&#10;&lt;h2 id="devsecops-파이프라인"&gt;DevSecOps 파이프라인&lt;/h2&gt;&#10;&lt;p&gt;CI/CD 파이프라인에 보안 검사를 넣는 방법을 다룹니다. SAST, DAST, SCA, 시크릿 탐지,&#10;컨테이너 보안, IaC 보안을 단계별로 안내하고, 각 항목이 ISO/IEC 18974의 어느 조항과&#10;연결되는지 매핑합니다.&lt;/p&gt;</description></item></channel></rss>