Back to INCF
GSoC 2026

Reusable DSOMM Security Pipeline for EBRAINS MIP Platform

The Medical Informatics Platform (MIP) currently lacks standardized automated governance for its federated infrastructure, leading to deployment friction and configuration drift. I plan to solve this by implementing a vendor-neutral CI/CD pipeline in GitHub Actions that automates Infrastructure-as-Code (IaC) validation and maturity assessment using the OWASP DSOMM framework. Key deliverables include a detailed DSOMM based infrastructure audit, an automated orchestration pipeline featuring IaC scanning and SBOM generation, and a reusable secure pipeline blueprint to enable scalable and reliable infrastructure management across the EBRAINS community.

Project details

Contributor

moghit-eou

Mentors

Not available

Technologies

Not listed in the archive