ossf / wg-securing-critical-projects

Helping allocate resources to secure the critical open source projects we all depend on.
Apache License 2.0
318 stars 34 forks source link

Adopt "Census I" as an archived Project/SIG under this WG #89

Open jeffmendoza opened 1 month ago

jeffmendoza commented 1 month ago

I have an odd request. I'd like to merge an archived project now called "census I" into this WG, keeping it archived. The reason is that I think it's important to continue to make it available.

Years ago I led a project to measure criticality, now often called "Census I". The report & supporting code are currently here: https://github.com/coreinfrastructure/census Interestingly enough, that report specifically noted the xz utility as especially concerning. Given the effort recently to insert a backdoor into xz, that seems prescient.

However, the coreinfrastructure (CII) project is no longer in existence, and in the long term we want to remove projects from it.

I think it's important for the OpenSSF to include this repository so that future work can easily refer to it.

Seem reasonable?

Please vote on this proposal below

jeffmendoza commented 1 month ago

+1

Amir-Montazery commented 1 month ago

+1

calebbrown commented 3 weeks ago

+1

david-a-wheeler commented 3 weeks ago

Clarification: The original request was from me, @david-a-wheeler . My thanks to all!

jeffmendoza commented 1 week ago

Hi @david-a-wheeler With approving votes and no objections, this is approved to nest under this WG! Please go ahead and open up a PR in the TAC repo using the template as described in the Project Lifecycle:

david-a-wheeler commented 1 week ago

Wonderful! Thanks for approving this admittedly odd request. I think it'll be good for everyone.

david-a-wheeler commented 1 week ago

I've asked Bennett to start the process. I have hopes that we can retain forwarding links from its old location, but I guess we'll see.