OpenChain-Project / Contribution-Process-Specification

This is a specification to develop a reference specification related to contribution process management for organizations.
Other
3 stars 1 forks source link

Way to Question / Respond between organizations to topics about processes, legal matters etc. #13

Open shanecoughlan opened 1 year ago

shanecoughlan commented 1 year ago

From Item 6 here: https://github.com/OpenChain-Project/Contribution-Process-Specification/issues/2

If a receiving organization (most likely a open source project) have questions as to the validity, internal approvals or other non technical questions there should be a process to address those from the contributing organization, similar to section 3.2.2 in the License Compliance specification (ISO:5230).

==

Shane: perhaps covers 3.2.1 and 3.2.2 from License Compliance ISO/IEC 5230:2020?

==

3.2 - Relevant tasks defined and supported

3.2.1 - Access

Maintain a process to effectively respond to external open source inquiries. Publicly identify a means by which a third party can make an open source compliance inquiry.

Verification material(s):

Rationale:

To ensure there is a reasonable way for third parties to contact the organization with regard to open source compliance inquiries and that the organization is prepared to effectively respond.

3.2.2 - Effectively resourced

Identify and Resource Program Task(s):

Verification material(s):

Rationale:

To ensure: i) program responsibilities are effectively supported and resourced and ii) policies and supporting processes are regularly updated to accommodate changes in open source compliance best practices.

ContiMary commented 1 year ago

I found this very confusing. why would an organization have this feedback mechanism when the project that is being contributed to will have its own mechanisms for even accepting the contribution, and should have a means to contact the person submitting the change. Are you thinking that the companies run compliance checks on every single contribution made to a public repository?