Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: Add links to GOSST email

...

...

  • Look again into SCR:CLR as a service to projects
  • Make sure our projects are keeping track of their dependencies, especially things that are EOL, especially things that are other Apache projects and EOL (example log4j v1)
    • Track the dependencies across our projects so we can see the combined-graph for the latest version of each ASF project. Work centrally to encourage that dependencies are not insecure, or excessively dated.
  • Facilitate direct funding efforts such as TideLift which provide direct financial support for developers to focus on matters such as security
  • How does OpenSSF Alpha and/or Omega fit with ASF
  • Look at the sponsored SOS rewards program
  • Looks at OpenSSF OSS Fuzz. See also mail from GOSST

WH Theme: Identify Critical projects / Help users pick secure projects

...

  • Look at OpenSSF SLSA/SBOM work (SLSA).  See also mail from GOSST
  • Consider adopting https://osv.dev/ (instead of CVE/CVSS). (These are not mutually exclusive)
  • We have no way to know who is using our projects, nor do we want to capture that data (so is the current vulnerability notification system sufficient?)

...