ossf / wg-vulnerability-disclosures

The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by helping mature and advocate well-managed vulnerability reporting and communication.
https://openssf.org
Apache License 2.0
175 stars 40 forks source link

WG Charter updates #106

Closed SecurityCRob closed 1 year ago

SecurityCRob commented 2 years ago

Hi. The OSSF TAC is seeking to get an issue(1) closed out. We want to ensure all working groups have a complete charter.md file and as I reviewed this group's file I noticed a few items that should be addressed please:

Thank you for attending to this matter!

(1) - https://github.com/ossf/tac/issues/9

annabellegoth2boss commented 2 years ago

A note on TSC contributors: link TSC to contributors under Section 2 (most likely the WG's contributors list - https://github.com/ossf/wg-vulnerability-disclosures/graphs/contributors)

Other relevant repos would be: github.com/ossf/oss-vulnerability-guide and [future repo for security researcher guide]

SecurityCRob commented 2 years ago

made initial changes to charter file. need to review with group and get approval

annabellegoth2boss commented 2 years ago

Have opened #107 to suggest some edits with regard to mission (mostly wordsmithing) and Maintainers being expected to stay active to retain their Maintainer status

vmbrasseur commented 2 years ago

At the 20220420 call, @JasonKeirstead and I agreed to create a new draft of the charter that, among other things, gets rid of the problematic TSC language.

We have a first draft of that in a Google Doc: https://docs.google.com/document/d/1XgG59KSbKh-lfuNs07OAZ_U18sO_g77YlNWNtGoBCq4/edit?usp=sharing

A lot of questions and concerns came up as we were working on this. Most of those are reflected in comments in the doc. We can review during the 20220504 call.

SecurityCRob commented 1 year ago

wg adopted charter 7dec2022