|
| 1 | +## Application for creating a new project at Sandbox stage |
| 2 | + |
| 3 | +### List of project maintainers |
| 4 | + |
| 5 | +The project has [4 maintainers](https://github.com/revanite-io/sci/graphs/contributors) from 4 different organizations: |
| 6 | + |
| 7 | +* Eddie Knight, Sonatype, @eddie-knight |
| 8 | +* Travis Truman, Independent, @trumant |
| 9 | +* Jason Meridth, GitHub, @jmeridth |
| 10 | +* Alex Speasmaker, USAA, @speas038 |
| 11 | + |
| 12 | +And one contributor, from a fifth organization: |
| 13 | + |
| 14 | +* Jennifer Power, RedHat, @jpower432 |
| 15 | + |
| 16 | +### Sponsor |
| 17 | + |
| 18 | +Most projects will report to an existing OpenSSF Working Group, although in some cases a project may report directly to the TAC. The project commits to providing quarterly updates on progress to the group they report to. |
| 19 | + |
| 20 | +* [ORBIT WG](https://github.com/ossf/wg-orbit) |
| 21 | + |
| 22 | +### Mission of the project |
| 23 | + |
| 24 | +The project must be aligned with the OpenSSF mission and either be a novel approach for existing areas, address an unfulfilled need, or be initial code needed for OpenSSF WG work. It is preferred that extensions of existing OpenSSF projects collaborate with the existing project rather than seek a new project. |
| 25 | + |
| 26 | +* Gemara, currently named "Simplified Compliance Infrastructure (SCI)", is a collection of schema describing data interchange formats for security and compliance activities and a Golang module for producing and consuming data conforming to these formats. The project's mission is to serve as a unifying, integration format between tools and applications that operate in the security and compliance space. SCI is currently used to model the catalog of compliance controls in the OSPS Baseline and in the FINOS Common Cloud Controls and is expected to be adopted by additional tools like darn/darnit, oscal-tempest, etc. |
| 27 | + |
| 28 | +**_NOTE: due to a naming collision with the existing OpenSSF Supply Chain Integrity WG, if this project is granted Sandbox phase status, it will be renamed Gemara._** |
| 29 | + |
| 30 | +### IP policy and licensing due diligence |
| 31 | + |
| 32 | +When contributing an existing Project to the OpenSSF, the contribution must undergo license and IP due diligence by the Linux Foundation (LF). |
| 33 | + |
| 34 | + * Gemara is currently licensed under the Apache 2.0 License and requires DCO signoff from all contributors |
| 35 | + * We will initiate this process shortly. |
| 36 | + |
| 37 | +### Project References |
| 38 | + |
| 39 | +The project should provide a list of existing resources with links to the repository, and if available, website, a roadmap, contributing guide, demos and walkthroughs, and any other material to showcase the existing breadth, maturity, and direction of the project. |
| 40 | + |
| 41 | +| Reference | URL | |
| 42 | +|---------------------|-----| |
| 43 | +| Repo | https://github.com/revanite-io/sci | |
| 44 | +| Website | https://www.revanite.io/sci | |
| 45 | +| Contributing guide | https://github.com/revanite-io/sci/blob/main/CONTRIBUTING.md | |
| 46 | +| Security.md | Once approved for Sandbox phase, we intend to adopt https://github.com/ossf/wg-orbit/blob/main/SECURITY.md | |
0 commit comments