Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

create a new SIG - Security Baseline SIG #562

Closed
Danajoyluck opened this issue Jul 16, 2024 · 1 comment
Closed

create a new SIG - Security Baseline SIG #562

Danajoyluck opened this issue Jul 16, 2024 · 1 comment

Comments

@Danajoyluck
Copy link

Proposed focus, intent, goals, and/or deliverables

The goal of this SIG is to evolve OpenSSF security baseline for Linux Foundation wide adoption.

For OpenSSF adoption of the security baseline, there needs to be a home for tracking the adoption, for maintainers to raise issues to refine the security baseline, merge the baseline back to TAC lifecycle, and for OpenSSF to develop the roadmap for the security baseline. It will provide a venue for early adopters to share their reusable code and findings with other maintainers. The pilot adoption builds the foundation for wider adoption of the security baseline in OpenSSF and in Linux Foundation.

This SIG creates a venue for other participating foundations to help evolve the OpenSSF security baseline into a security baseline that can be applied to a broad range of software-based projects. The group will define the right level of risks that the security baseline is applicable for, the effectiveness measurement of the security baseline, and the adoption path of the security baseline at the minimum.

Members of this group will be from various Linux foundations and entities outside of Linux Foundation. Reducing duplicate effort and achieving a higher level of security across Linux Foundation participating foundations is one of the goals of the group.

List SIG Lead(s)

The SIG must have a minimum of 1 Lead

  • Eddie Knight, OpenSSF Security Insights lead, Sonatype, GitHub ID: eddie-knight
  • Michael Lieberman, OpenSSF GUAC lead, Kusari, GitHub ID: mlieberman85

List of interested individuals

The SIG have a minimum of 3 members with 2 different organizational affiliations.

  • Adolfo "Puerco" García Veytia, CNCF kubernetes SIG Release Technical Lead, OpenSSF Protobom, OpenVEX maintainer, Staklock, GitHub ID: puerco
  • Justin Cappos, CNCG TUF, in-toto, Uptane, OpenSSF gittuf maintainer, New York University. GitHUb ID: JustinCappos
  • David Wheeler, OpenSSF Best Practice Badge maintainer, OpenSSF, GitHub ID: david-a-wheeler
  • Dana Wang, OpenSSF security baseline maintainer, OpenSSF, GitHub ID: danajoyluck
@SecurityCRob
Copy link
Contributor

This was discussed in the 16july2024 WG call and the group agreed to adopt the Baseline as a SIG of the BEST WG. Welcome folks! We're looking forward to collaborating on this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants