DUE TO SPAM, SIGN-UP IS DISABLED. Goto Selfserve wiki signup and request an account.
...
- Have a better EOL policy with defined communication routes, policy for CVE in EOL releases. See also this thread about Attic
- Have a policy around projects that depend on other EOL projects (ASF and non-ASF)
- More 2FA requirements
- Consider if projects that are not releasing regularly are really healthy. Could they realistically respond to a security vulnerability in a reasonable time frame?
- Make sure we upgrade our CNA CVE process to JSON 5.0 to make use of the additional record data
- We probably ought to fix every CVE entry so the version_data works well for 5.0, see for example https://vulnogram.github.io/seaview/?CVE-2021-44549
- Would OpenSSF sigstore be a future replacement for current signing policies. See also mail from GOSST
- Should have more complete policy around production of "builds" https://www.apache.org/legal/release-policy.html#compiled-packages
- Look at OpenSSF AllStar
- Give more guidance on how to deal with 'low severity' issues to avoid them 'hanging around' and distracting from more urgent things
WH Theme: Preventing Defects
...