You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 3 Next »

Possible initiatives and things we've discussed doing as part of the work for this meeting.  In no particular order

  • Make sure our users know what they should be doing to find out about updates, EOL, CVEs
  • Consider if projects that are not releasing regularly are really healthy.  Could they realistically respond to a security vulnerability in a reasonable time frame?
  • Have a better EOL policy with defined communication routes, policy for CVE in EOL releases.
  • Look again into SCR:CLR as a service to projects
  • Look at 2FA for Apache
  • Make sure we upgrade our CNA CVE process to JSON 5.0 to make use of the additional record data
  • Get involved with various OpenSSF initiatives
    • Is the training something we should promote to committers
    • How can we make the scorecard better for ASF projects
    • How can we make the critical projects list better for ASF projects
    • How does Alpha and/or Omega fit with ASF
    • Would sigstore be a future replacement for current signing policies
    • Look at SLSA/SBOM work
  • No labels