Skip to content

Discussion: New TI process realignment #600

@marcelamelara

Description

@marcelamelara

The labs process proposal and updates to the sandbox project entry requirements have raised several broader issues regarding TI gives and gets, Project sponsorships and repo creation. As authors of these two proposals, @justaugustus and I also had a private discussion on these topics.

This issue intends to record and summarize specific points/gaps raised in these two proposals that probably warrant a bit more discussion, rather than attempting to incorporate all of these points into these proposals.

From these discussions, we have identified the following needs that are not clearly covered or need revision in our current TI lifecycle docs:

  1. A process for small single-maintainer/single-org projects to join OpenSSF at sandbox level -- proposed in Add the OpenSSF labs process #421, Relax Sandbox entry requirements and clarify WG sponsorship #599
  2. A process for WGs and SIGs to create new GitHub repositories for new software/spec projects -- proposed in Add the OpenSSF labs process #421, possible alternative
  3. Clarity on the definition of a Project -- Our current docs heavily focus on software, but specs are also very common. Both need GH repos that meet specific security practices.
  4. Clarity on which entities / TIs can sponsor and oversee Projects -- Currently, the TAC may sponsor a Project directly (per Relax Sandbox entry requirements and clarify WG sponsorship #599, we want to move away from this), and process for hosting Projects under SIGs (increasingly common) is underspecified/unclear.
  5. Clarity on Security Baseline for spec vs. software Projects -- When do spec repos need to start applying stricter security requirements?
  6. Realignment on TI gives and gets will likely be needed based on these changes

Metadata

Metadata

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions