Skip to content

Conversation

balteravishay
Copy link
Contributor

Update TAC with the great work done in the BEST practices WG

@balteravishay balteravishay requested a review from a team as a code owner July 3, 2025 20:25
Signed-off-by: balteravishay <[email protected]>
@balteravishay balteravishay force-pushed the avbalter/bp-tac-update branch from 3232946 to 93d9560 Compare July 3, 2025 20:26
Co-authored-by: Georg Kunz <[email protected]>
Signed-off-by: Avishay Balter <[email protected]>
Copy link
Member

@steiza steiza left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lots of good stuff in here - I love all the guides and the courses we're working on.

This isn't a problem to solve today, but the answer to "what practices does OpenSSF recommend I follow to secure my project?" is starting to get quite complicated with the Best Practice badge, Scorecard, and the upcoming Baseline. These projects do serve different audiences and tools - I love how the Best Practice badge lets you explain how you meet a security capability even if it isn't one we can automatically detect - but we need some combination of convergence and / or explainers to point people in the right direction.

Something like: "Are you an open source maintainer? Check out Best Practices badge! Are you an OSPO or a consumer of open source? Use Scorecard. Are you in a foundation / trying to meet a compliance framework? Check out Baseline." That's a bit off the cuff and may not be 100% correct, but imagine how confusing this is for people who are completely outside the OpenSSF!

Co-authored-by: Arnaud J Le Hors <[email protected]>
Signed-off-by: Avishay Balter <[email protected]>
@marcelamelara marcelamelara added the TI Update Quarterly TI update. Needs 5 approvals, 7d review. label Jul 11, 2025
Copy link
Contributor

@marcelamelara marcelamelara left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @balteravishay !

#### **Status Update**

* Continued maintenance and security updates.
* Resolved subtle problem that was preventing ONAP from earning a gold badge.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pardon my ignorance, what is ONAP?


#### **Status Update**

* LFD121 labs are being translated into Japanese\!
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is great! Not directly related to the BEST WG, but I'm curious whether this translation work is being done by a contractor or if this being driven by a community member? The SLSA spec has received a few localization requests (incl. Japanese), and it would be great to continue the trend of having OpenSSF resources be available in multiple languages.

* A way to formally declare maintenance/production level intent for OSS project
* How to handle freshness of dependencies?
* Guidance about testing for OSS projects.
* Guidance on how to ensure that executables match their putative source code.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This sounds like a potential collaboration opportunity with SLSA.

Co-authored-by: Marcela Melara <[email protected]>
Signed-off-by: Zach Steindler <[email protected]>
@steiza steiza merged commit e27db46 into ossf:main Aug 19, 2025
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
TI Update Quarterly TI update. Needs 5 approvals, 7d review.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

6 participants