Collaboration with eclipse foundation among others on secure standard SDLC for open source #10
KorvinSzanto
started this conversation in
General
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
I just learned about this today and I'm excited to join the mailing list and track progress:
https://eclipse-foundation.blog/2024/04/02/open-source-community-cra-compliance/
Unfortunately it seems the only mailing list I can join is an outbound only one, and given that it's a mailing list, I can't see any history or track on the current state of things. Could someone involved in this mailing list summarize where things are currently and maybe advise on the best way to contribute?
For a bit of context the PHP-FIG worked on PSR-9 and PSR-10 which dealt with disclosing findings and accepting reports respectively years ago but never really finished, partially due to wanting to wait for other outside specifications to be finalized, partially due to lack of interest. My understanding is that the Eclipse et al initiative is far broader than that and would include things like how a project should be tested and how code changes should be reviewed and accepted, is that correct?
Beta Was this translation helpful? Give feedback.
All reactions