Skip to content

Conversation

evankanderson
Copy link
Contributor

When Minder was submitted to the OpenSSF, there was not a clear fit for the project in the existing working groups. The ORBIT (Open Resources for Baselines, Interoperability, and Tooling) seems like a clearer fit for Minder's ability to assess repositories and other supply chain resources for policy and control compliance, as we are actively participating in baseline conversations and looking to build automated assessments and remediations for baseline controls.

This records the move; it also updates the Security Insights Spec and Security Baseline project's move to the ORBIT WG.

@evankanderson evankanderson requested a review from a team as a code owner July 25, 2025 22:28
@marcelamelara
Copy link
Contributor

@ware @eddie-knight As WG chairs, can you both please confirm this transfer from ST to ORBIT?

@ware
Copy link
Contributor

ware commented Aug 5, 2025

I confirm @marcelamelara. I'm sad to see them move, but very happy I was able to foster their donation to OpenSSF but this is the right move for them.

Copy link
Member

@justaugustus justaugustus left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving the move, but we've got to resolve the comment on changes to the lifecycle document.

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Following the discussions in #497, I don't believe want updates to the lifecycle documents.

Other @ossf/tac members — Thoughts here?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we have a good way to fix e.g. broken links like https://minder-docs.stacklok.dev/, which is no longer functioning.

Copy link
Contributor

@lehors lehors Aug 5, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we have a good way to fix e.g. broken links like https://minder-docs.stacklok.dev/, which is no longer functioning.

Yeah, that's called a redirect and if people could use that instead of tearing down websites and web pages we'd all be better off. :-(

(sorry for the rant, I know you have no control over that)

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Filed this for discussion: #509

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@evankanderson we will work on a way to better track project metadata with #509, for now can you revert the changes to process/project-lifecycle-documents/minder_sandbox_stage.md in this pull request?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reverted.

Signed-off-by: Evan Anderson <[email protected]>
@evankanderson
Copy link
Contributor Author

(I think this needs @justaugustus to update his "request changes" review, and then a merge)

Copy link
Member

@justaugustus justaugustus left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @evankanderson!

@justaugustus justaugustus merged commit 39d9f9f into ossf:main Aug 12, 2025
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

8 participants