Skip to content

Commit

Permalink
Merge pull request #335 from jeffmendoza/wg-scp
Browse files Browse the repository at this point in the history
Propose Securing Critical Project WG to Incubating
  • Loading branch information
SecurityCRob authored Jun 10, 2024
2 parents 7a6aec5 + 37e94f5 commit cee5bad
Show file tree
Hide file tree
Showing 2 changed files with 61 additions and 1 deletion.
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -56,7 +56,7 @@ The following Technical Initiatives have been approved by the TAC. You may learn
| Security Tooling | https://github.com/ossf/wg-security-tooling | [Meeting Notes](https://docs.google.com/document/d/1jzxhzIfkOMTagpeFWYoZpMKwHYeO4Gc7Eq5FcMFEw2c/edit#heading=h.wdz394z3k3h2) | Incubating |
| Security Best Practices | https://github.com/ossf/wg-best-practices-os-developers | [Meeting Notes](https://github.com/ossf/wg-best-practices-os-developers/blob/main/meeting-minutes.md) | [Graduated](process/wg-lifecycle-documents/BEST_practices_wg_graduation_stage.md) |
| Metrics & Metadata | https://github.com/ossf/wg-metrics-and-metadata | [Meeting Notes](https://docs.google.com/document/d/14_ILDhSK3ymKqUTQeQBRgJKgfiy_ePoGZIe8s7p3K5E/edit) | Incubating |
| Securing Critical Projects | https://github.com/ossf/wg-securing-critical-projects | [Meeting Notes](https://docs.google.com/document/d/1GFslP6elYCx27TUitdigDr1gsOItYkL0Vq7hTB9y4Lo/edit) | Incubating |
| Securing Critical Projects | https://github.com/ossf/wg-securing-critical-projects | [Meeting Notes](https://docs.google.com/document/d/1GFslP6elYCx27TUitdigDr1gsOItYkL0Vq7hTB9y4Lo/edit) | [Incubating](process/wg-lifecycle-documents/securing_critical_projects_incubating_stage.md) |
| Supply Chain Integrity | https://github.com/ossf/wg-supply-chain-integrity | [Meeting Notes](https://docs.google.com/document/d/1xPs2sSbH3I9Ich7OyLOzl85oJshnK8Q6WoAgREE5-zA/edit) | Incubating |
| Securing Software Repositories | https://github.com/ossf/wg-securing-software-repos | [Meeting Notes](https://docs.google.com/document/d/1-f6m442MHg9hktrbcp-4sM9GbZC3HLTpZPpxMXjMCp4/edit) | [Graduated](process/wg-lifecycle-documents/Securing_software_repositories_graduation_stage.md) |
| End Users | https://github.com/ossf/wg-endusers | [Meeting Notes](https://docs.google.com/document/d/1abI65H4pF5y8YtA2_TuDBAaI47v9mTfpr5mwVvccX_I/edit) | Incubating |
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,60 @@
## Securing Critical Projects Working Group incubation application

### List WG Chair(s) and or Vice Chair

The WG must have a minimum of 1 Chair

* "Amir Montazery, Open Source Technology Improvement Fund, Inc, Amir-Montazery"
* "Jeff Mendoza, Kusari, Inc, jeffmendoza"

Check failure on line 8 in process/wg-lifecycle-documents/securing_critical_projects_incubating_stage.md

View workflow job for this annotation

GitHub Actions / Check Spelling

`jeffmendoza` is not a recognized word. (unrecognized-spelling)

### Working Group (WG) has met all Sandbox requirement

* Applying directly to Incubating

### List of regular contributors

The WG must have a minimum of 5 contributors from at least 3 different
organizations attending regularly.

* Jeff Mendoza, Kusari
* Amir Montazery, Open Source Technology Improvement Fund, Inc
* Caleb Brown, Google
* David Edelsohn, IBM
* David C Stewart, Intel
* David A. Wheeler, LF
* Randall T. Vásquez, Gentoo/Homebrew/SKF
* Yotam Perkal, Rezilion

### Mission of the Working Group

The WG must have a charter or mission statement for review by TAC

* https://github.com/ossf/wg-securing-critical-projects/blob/main/MVSR.md

### Governance

WG must have documented, initial group governance.

* https://github.com/ossf/wg-securing-critical-projects/blob/main/CHARTER.md

WG must have met publicly at least 5 times in the last quarter since becoming
Sandbox

* 2024: https://docs.google.com/document/d/1j_efLVDXGoKgfHHZbJtpBxd_Gso1ghHBdK3NfEVc15o/edit?usp=sharing
* 2020-2023: https://docs.google.com/document/d/1GFslP6elYCx27TUitdigDr1gsOItYkL0Vq7hTB9y4Lo/edit#heading=h.n1an2kl9m54e
* https://www.youtube.com/playlist?list=PLVl2hFL_zAh-cAfx6y4k-fODfbHeQzb_O

WG must have defined Contributor Guide

* https://github.com/ossf/wg-securing-critical-projects?tab=readme-ov-file#operations

Reference | URL |
|-----------------------|-----|
| Repo | https://github.com/ossf/wg-securing-critical-projects |
| Meeting Agenda | https://docs.google.com/document/d/1j_efLVDXGoKgfHHZbJtpBxd_Gso1ghHBdK3NfEVc15o/edit?usp=sharing |
| OSSF Calendar Entry | https://www.google.com/calendar/event?eid=MmpuZGJiZjBvaGpqMXVuOGNpYW1jMjgyOGZfMjAyNDA1MjNUMTYwMDAwWiBzNjN2b2VmaHA1aTlwZmx0YjVxNjduZ3Blc0Bn&ctz=America/New_York |
| Website | |
| Contributing guide | https://github.com/ossf/wg-securing-critical-projects?tab=readme-ov-file#operations |
| Security.md | https://github.com/ossf/wg-securing-critical-projects/blob/main/SECURITY.md |
| code-of-conduct.md | https://github.com/ossf/wg-securing-critical-projects/blob/main/code-of-conduct.md |
| Other | |

0 comments on commit cee5bad

Please sign in to comment.