DUE TO SPAM, SIGN-UP IS DISABLED. Goto Selfserve wiki signup and request an account.
...
- Require a minimum of 3 PPMC members to have attended a (yet to be written) training course on Vulnerability handling at the ASF before the podling is allowed to graduate
- Require projects to maintain a security team of at least 3 people all of whom have undertaken the training described in the previous point
- Is OpenSSF training something we should promote to committers
- Educate projects on the selection of dependencies, and their upkeep (see also "Help users pick secure projects") (This could possibly be OpenSSF Scorecards)
Theme: Improving our process and policy
- Have a better EOL policy with defined communication routes, policy for CVE in EOL releases.
- More 2FA requirements
- Consider if projects that are not releasing regularly are really healthy. Could they realistically respond to a security vulnerability in a reasonable time frame?
- Make sure we upgrade our CNA CVE process to JSON 5.0 to make use of the additional record data
- Would OpenSSF sigstore be a future replacement for current signing policies
- Should have more complete policy around production of "builds" https://www.apache.org/legal/release-policy.html#compiled-packages
- Look at OpenSSF AllStar
- Sometimes communication with vulnerability reporters breaks down, is it time to have a more structured tool for handling reports which forces the process? or just have our CVE tool give reminders / require checkboxes?
...
- Look again into SCR:CLR as a service to projects
- Make sure our projects are keeping track of their dependencies, especially things that are EOL, especially things that are other Apache projects and EOL (example log4j v1)
- Facilitate direct funding efforts such as TideLift which provide direct financial support for developers to focus on matters such as security
- How does OpenSSF Alpha and/or Omega fit with ASF
- Look at the sponsored SOS rewards program
- Looks at OpenSSF OSS Fuzz
WH Theme: Identify Critical projects / Help users pick secure projects
...
- Look at OpenSSF SLSA/SBOM work (SLSA)
- Consider adopting https://osv.dev/
(instead of CVE/CVSS). (These are not mutually exclusive) - We have no way to know who is using our projects, nor do we want to capture that data (so is the current vulnerability notification system sufficient?)
...