DUE TO SPAM, SIGN-UP IS DISABLED. Goto Selfserve wiki signup and request an account.
...
- Have a better EOL policy with defined communication routes, policy for CVE in EOL releases.
- Have a policy around projects that depend on other EOL projects (ASF and non-ASF)
- More 2FA requirements
- Consider if projects that are not releasing regularly are really healthy. Could they realistically respond to a security vulnerability in a reasonable time frame?
- Make sure we upgrade our CNA CVE process to JSON 5.0 to make use of the additional record data
- We probably ought to fix every CVE entry so the version_data works well for 5.0, see for example https://vulnogram.github.io/seaview/?CVE-2021-44549
- Would OpenSSF sigstore be a future replacement for current signing policies. See also mail from GOSST
- Should have more complete policy around production of "builds" https://www.apache.org/legal/release-policy.html#compiled-packages
- Look at OpenSSF AllStar
- Sometimes communication with vulnerability reporters breaks down, is it time to have a more structured tool for handling reports which forces the process? or is it more people engagement? or can we just require checkboxes before allocating CVE names in our existing tool?
...
- Look again into SCR:CLR as a service to projects
- Make sure our projects are keeping track of their dependencies, especially things that are EOL, especially things that are other Apache projects and EOL (example log4j v1)
- Track the dependencies across our projects so we can see the combined-graph for the latest version of each ASF project. Work centrally to encourage that dependencies are not insecure, or excessively dated.
- Facilitate direct funding efforts such as TideLift which provide direct financial support for developers to focus on matters such as security
- How does OpenSSF Alpha and/or Omega fit with ASF
- Look at the sponsored SOS rewards program
- Looks at OpenSSF OSS Fuzz. See also mail from GOSST
WH Theme: Identify Critical projects / Help users pick secure projects
...
- Look at OpenSSF SLSA/SBOM work (SLSA). See also mail from GOSST
- Consider adopting https://osv.dev/
(instead of CVE/CVSS). (These are not mutually exclusive) - We have no way to know who is using our projects, nor do we want to capture that data (so is the current vulnerability notification system sufficient?)
...