ossf / osv-schema

Open Source Vulnerability schema.
https://ossf.github.io/osv-schema/
Apache License 2.0
176 stars 75 forks source link

Proposed legal & governance improvements for the OpenSSF #224

Closed hythloda closed 1 month ago

hythloda commented 7 months ago

There have been some formalizations with governance for projects in the OpenSSF. I think these are all for the better, but if you have a concern, PLEASE let me know soon! I plan to wait for 1 month (2024-03-12) before starting down this path.

Here is the full documents

  1. LLC Series. LF Legal would like this project to become a "series" within "LF Projects, LLC". This creates a legal identity for the project & provides various legal protections. We hope to not need legal protections, but it's best to have them. To do that, the TSCs to be listed on the project page on who is in the TSC.

The TSC then needs to vote on the Technical Charter Draft

Make sure the mission is accurate.

Choose a delegate to sign the Contribution Agreement Draft

Then the LF will submit the Series Agreement Draft

Please let me know if you have any questions or concerns.

oliverchang commented 3 months ago

sorry for the delays on this. https://github.com/ossf/osv-schema/pull/228 is approved.

re the contribution agreement draft, I'm not sure any of us understand the legal implications of this as none of us are lawyers.

I'm also not sure there is any owner who can claim the "OSV-Schema" trademark to begin with, given that we started this project/repo in the OSSF -- which I would've assumed meant that it belonged to the OSSF to begin with?