ossf / wg-supply-chain-integrity

Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the code they maintain, produce and use.
https://openssf.org
Apache License 2.0
175 stars 33 forks source link

Tracking Issue: Move Secure Software Factory Repo to OpenSSF! #47

Closed dlorenc closed 1 year ago

dlorenc commented 2 years ago

The Secure Software Factory (https://github.com/thesecuresoftwarefactory/ssf) that was demoed on the 19th is now approved to move into the OpenSSF under this WG.

We have a few logistical items to handle:

We should aim to do this by Tuesday for the announcement on Wednesday!

dlorenc commented 2 years ago

cc @mlieberman85

dlorenc commented 2 years ago

Just to clarify for anyone following along - after the demo meeting on 19th and a discussion in Slack on the 20th we've formally accepted the SSF to join the Supply Chain Integrity WG! This issue is tracking the logistical details required for the move itself.

mlieberman85 commented 2 years ago

@dlorenc I think it's worthwhile to maybe do another refresh of this. We've been merged in, and I worked with Jory and others to make sure org falls under LF/OpenSSF ownership, however I think there might be a handful of license, CoC and other things that might be missing.

dlorenc commented 2 years ago

@mlieberman85 could you send an update to the README to add the FRSCA project, then close this out?

mlieberman85 commented 2 years ago

Yes, let me do that right now.

melba-lopez commented 1 year ago

@mlieberman85 this issue appears to have been resolved per PR#54. Is that correct?

mlieberman85 commented 1 year ago

Yes that is correct. This can be closed