Skip to content

Conversation

jeffmendoza
Copy link
Member

No description provided.

@jeffmendoza jeffmendoza requested a review from a team as a code owner July 21, 2025 22:30
@marcelamelara marcelamelara added the TI Update Quarterly TI update. Needs 5 approvals, 7d review. label Jul 22, 2025
Copy link
Contributor

@marcelamelara marcelamelara left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @jeffmendoza ! I've got a couple clarifying questions.


### Up Next

- Critical Open Source Software Managed Audit Program
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What do you imagine the role of the SCP WG in this program?

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this is the same question, but is this a partnership with OSTIF? Or is this a potential future OpenSSF TI Managed Audit SIG inside of SCP WG?

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@jeffmendoza @Amir-Montazery Can you please update this point with a quick summary of our discussion at the 7/22 TAC meeting.


### Up Next

- Now that we have a good idea of critical projects, OSTIF is proposing a Managed Audit Program to go out and do the following to projects identified as critical:
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Interesting! Where would the funding come from for this work? I know the OpenSSF TI funding has been used for security audits of OpenSSF TIs (which makes sense), but I don't think we'd use TI funding for auditing external projects (or if we did, due to the budget it wouldn't be more than a few per year)? Maybe this would be more in Alpha Omega's wheelhouse?

Copy link
Contributor

@lehors lehors Jul 22, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In my opinion this has been an issue for a long time: where does this WG stop and where does A.O. start?


### Up Next

- Critical Open Source Software Managed Audit Program
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this is the same question, but is this a partnership with OSTIF? Or is this a potential future OpenSSF TI Managed Audit SIG inside of SCP WG?

Copy link
Member

@justaugustus justaugustus left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@jeffmendoza — Looks great. I have the same questions as Marcela and Zach!

Quota elaboration.

Signed-off-by: Jeff Mendoza <[email protected]>
Copy link
Contributor

@mlieberman85 mlieberman85 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
TI Update Quarterly TI update. Needs 5 approvals, 7d review.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

8 participants