ossf / tac

Technical Advisory Council
https://openssf.org
Other
109 stars 59 forks source link

[Technical Initiative Funding Request]: Cloud credits for gittuf's GitHub app #378

Closed adityasaky closed 2 weeks ago

adityasaky commented 2 months ago

Technical Initiative

gittuf

Lifecycle Phase

sandbox

Funding amount

$50 a month

Problem Statement

We have been working on a GitHub app for gittuf hosted on Google Cloud. We need cloud credits to serve the app for users who want to add it to their repositories.

Who does this affect?

The solution is for the gittuf developers / maintainers who want to run the app.

Have there been previous attempts to resolve the problem?

No

Why should it be tackled now and by this TI?

gittuf is part of the OpenSSF sandbox, and the GitHub app would help repositories adopt gittuf in a user friendly manner.

Give an idea of what is required to make the funding initiative happen

The cloud credits are approved and gittuf maintainers are given access to Google Cloud via the OpenSSF. Following that, the maintainers (myself, @wlynch, etc.) will operate the GitHub app.

What is going to be needed to deliver this funding initiative?

Cloud credits or access to a Google Cloud project backed by an OpenSSF controlled billing account.

Are there tools or tech that still need to be produced to facilitate the funding initiative?

No response

Give a summary of the requirements that contextualize the costs of the funding initiative

The estimated cost would cover the cost of pulling together several Google Cloud services (cloud run, KMS, secrets management, etc.) to operate the gittuf GitHub app.

Who is responsible for doing the work of this funding initiative?

Aditya Sirish A Yelgundhalli (@adityasaky)

Who is accountable for doing the work of this funding initiative?

Aditya Sirish A Yelgundhalli (@adityasaky)

If the responsible or accountable parties are no longer available, what is the backup contact or plan?

Billy Lynch (@wlynch)

What license is this funding initiative being used under?

Apache 2.0

Code of Conduct

List the major milestones by date and identify the overall timeline within which the technical initiative plans to accomplish their goals. Any payments for services, sponsorships, etc., will require LF Legal and Financial review.

We expect the app to be live and serving repositories that opt in to using it within a month of the funding request being approved.

If this is a request for funding to issue a contract, then OpenSSF will issue that contract. Please provide a Statement of Work (SOW) that we may review. Any contracting action will take 4-6 weeks to issue.

No response

SecurityCRob commented 1 month ago

I suggest we approve this request until the end of 2025, at which time the project can demonstrate progress and reapply. That would be 15mos x $50/mo = $750 for this request

riaankleinhans commented 1 month ago

/vote

git-vote[bot] commented 1 month ago

Vote created

@riaankleinhans has called for a vote on [Technical Initiative Funding Request]: Cloud credits for gittuf's GitHub app (#378).

The members of the following teams have binding votes: Team
@ossf/tac

Non-binding votes are also appreciated as a sign of support!

How to vote

You can cast your vote by reacting to this comment. The following reactions are supported:

In favor Against Abstain
👍 👎 👀

Please note that voting for multiple options is not allowed and those votes won't be counted.

The vote will be open for 1month 11days 13h 26m 24s. It will pass if at least 70% of the users with binding votes vote In favor 👍. Once it's closed, results will be published here as a new comment.

riaankleinhans commented 1 month ago

Gitvote was added as a tool to test for stream lining the TI Funding process. The members of the GH group "TAC" can vote by commenting with an +1. -1 or eye on the Gitvote block in this issue. Until the TAC is satisfied with the process the GitVote outcome would not be binding.

Community members can show their support by also voting, however only the "TAC" GH Group's votes will count.

The current passing threshold is 70% and the committee is the TAG GH group. The vote say open fo 6 week and an announcement is sent on the GH/TAC/Discussion

All these parameters can by fine tuned or changed here Please reach out if you have any questions.

SecurityCRob commented 1 month ago

A quorum of the TAC met on 17Sept to discuss Q3 TI Funding Requests.

Consensus of the group was to approve this funding request. We'll pass this to staff to manage from this point.

git-vote[bot] commented 1 month ago

Vote status

So far 22.22% of the users with binding vote are in favor (passing threshold: 70%).

Summary

In favor Against Abstain Not voted
2 0 0 7

Binding votes (2)

User Vote Timestamp
marcelamelara In favor 2024-09-23 20:36:38.0 +00:00:00
SecurityCRob In favor 2024-09-23 18:18:22.0 +00:00:00
@steiza Pending
@torgo Pending
@mlieberman85 Pending
@bobcallaway Pending
@lehors Pending
@camaleon2016 Pending
@sevansdell Pending
git-vote[bot] commented 4 weeks ago

Vote status

So far 33.33% of the users with binding vote are in favor (passing threshold: 70%).

Summary

In favor Against Abstain Not voted
3 0 0 6

Binding votes (3)

User Vote Timestamp
marcelamelara In favor 2024-09-23 20:36:38.0 +00:00:00
mlieberman85 In favor 2024-10-02 15:09:45.0 +00:00:00
SecurityCRob In favor 2024-09-23 18:18:22.0 +00:00:00
@steiza Pending
@torgo Pending
@bobcallaway Pending
@lehors Pending
@camaleon2016 Pending
@sevansdell Pending
lehors commented 4 weeks ago

/cancel-vote

git-vote[bot] commented 4 weeks ago

Vote cancelled

@lehors has cancelled the vote in progress in this issue.

sevansdell commented 3 weeks ago

This vote tool is also cancelled. How are we proceeding instead?

steiza commented 3 weeks ago

This vote tool is also cancelled. How are we proceeding instead?

Yeah, we got a little over-zealous when trying out the new voting application. This was also approved by a quorum of the TAC on Sept 17th: https://github.com/ossf/tac/issues/378#issuecomment-2371324664.

Coincidentally, this was also the other issue I was asking @riaankleinhans about at the TAC meeting yesterday. On the funding project board it's sitting in Funding Approved but hasn't yet moved to Funding in Execution.

riaankleinhans commented 2 weeks ago

I moved this allong on the Project board. In communication with the project. @adityasaky do you think we can close this issue?

adityasaky commented 2 weeks ago

Yes, I believe so! Thanks all!