Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: Items from comments from Google and OpenSSF

...

  • Require a minimum of 3 PPMC members to have attended a (yet to be written) training course on Vulnerability handling at the ASF before the podling is allowed to graduate
  • Require projects to maintain a security team of at least 3 people all of whom have undertaken the training described in the previous point
  • Is OpenSSF training something we should promote to committers
  • Educate projects on the selection of dependencies, and their upkeep (see also "Help users pick secure projects") (This could possibly be OpenSSF Scorecards)

Theme: Improving our process and policy

...

  • Look again into SCR:CLR as a service to projects
  • Make sure our projects are keeping track of their dependencies, especially things that are EOL, especially things that are other Apache projects and EOL (example log4j v1)
  • Facilitate direct funding efforts such as TideLift which provide direct financial support for developers to focus on matters such as security
  • How does OpenSSF Alpha and/or Omega fit with ASF
  • Look at the sponsored SOS rewards program
  • Looks at OpenSSF OSS Fuzz

WH Theme: Identify Critical projects / Help users pick secure projects

...

  • Look at OpenSSF SLSA/SBOM work (SLSA)
  • Consider adopting https://osv.dev/ (instead of CVE/CVSS). (These are not mutually exclusive)
  • We have no way to know who is using our projects, nor do we want to capture that data (so is the current vulnerability notification system sufficient?)

...