Project "Eclipse: Open Registry Security Gateway for Open VSX"
Projekt "Eclipse: Open Registry Security Gateway for Open VSX"
This service agreement concerns the FOSS component "Eclipse Open VSX" and the associated technical specification Eclipse SCINTX, covering the work needed to complete a functional reference implementation of the specification which is intended to pave the road for an open ecosystem where heterogenously operated repositories of plug-ins for integrated development environments (IDE) that are compatible with the VS Code architecture can be scanned and verified by independent third-party security service-providers. Achieving this entails studying the functional requirements specified by the open specification SCINTX, in order to design an application programming interfaces (API) and a system architecture that realizes these requirements, relying on existing open specifications and FOSS components for the implementation details where applicable, then implementing the design into a usable software system and configuration as per the state-of-the-art in the field. The work also entails studying the public APIs of two commonly used open, free security-scanning services in order to implement a provider-specific adapter for each of them as an example, within the architectural model designed for the gateway. Finally, a software-development kit (SDK) is to be produced, in order to facilitate the creation of adapters for more third-party providers and integrations. This work is intended to increase the security of the supply chain of FOSS infrastructure, and of the software industry in general, where third-party plug-ins are often used to add productive functionality to software IDEs, but can also be abused as attack vectors due to the access they are granted to development environment resources, thus threatening much more than the systems they immediately touch.