Skip to content

Latest commit

 

History

History
43 lines (32 loc) · 1.81 KB

File metadata and controls

43 lines (32 loc) · 1.81 KB

OpenShield Roadmap: July 2026 to June 2027

This roadmap communicates direction rather than a delivery guarantee. Security fixes and community needs may change priorities. Work is accepted only through reviewed issues and pull requests.

July–September 2026

  • Complete OpenSSF Best Practices Silver readiness and evidence.
  • Expand enterprise Azure coverage while preserving low false-positive rates.
  • Improve scanner inventory error handling and rule test coverage.
  • Reconcile documentation, website rule counts and current APIs.

October–December 2026

  • Stabilize the scanner and REST API contracts for a supported 1.0 release.
  • Improve deployment, upgrade and database migration guidance.
  • Expand Sentinel detections and operational security monitoring.
  • Establish signed release artifacts and public verification instructions.

January–March 2027

  • Add organization-scale scanning and clearer multi-subscription workflows.
  • Improve accessibility and internationalization readiness in user interfaces.
  • Expand evidence-based compliance reporting and exception handling.
  • Evaluate a provider interface for future clouds without weakening Azure support.

April–June 2027

  • Review reliability, performance and recovery objectives using production feedback.
  • Mature compatibility, deprecation and long-term maintenance policies.
  • Reassess readiness for OpenSSF Gold without claiming it prematurely.

Explicitly out of scope for this period

  • Automatic remediation without explicit operator confirmation.
  • Claims of formal certification for CIS, ISO 27001, SOC 2 or NIST.
  • Collection of Azure resource contents, secrets or customer workload data.
  • Guaranteed detection of every cloud vulnerability or configuration risk.
  • Multi-cloud parity until the Azure implementation and provider boundary are stable.