Skip to content

Commit 8ff2165

Browse files
committed
clarify project renaming outcome if approved
Signed-off-by: Travis Truman <trumant@gmail.com>
1 parent 10d8be7 commit 8ff2165

File tree

1 file changed

+4
-2
lines changed

1 file changed

+4
-2
lines changed

process/project-lifecycle-documents/sci_sandbox_stage.md renamed to process/project-lifecycle-documents/gemera_sandbox_stage.md

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -23,13 +23,15 @@ Most projects will report to an existing OpenSSF Working Group, although in some
2323

2424
The project must be aligned with the OpenSSF mission and either be a novel approach for existing areas, address an unfulfilled need, or be initial code needed for OpenSSF WG work. It is preferred that extensions of existing OpenSSF projects collaborate with the existing project rather than seek a new project.
2525

26-
* SCI is a collection of schema describing data interchange formats for security and compliance activities and a Golang module for producing and consuming data conforming to these formats. The project's mission is to serve as a unifying, integration format between tools and applications that operate in the security and compliance space. SCI is currently used to model the catalog of compliance controls in the OSPS Baseline and in the FINOS Common Cloud Controls and is expected to be adopted by additional tools like darn/darnit, oscal-tempest, etc.
26+
* Gemera (current name) is a collection of schema describing data interchange formats for security and compliance activities and a Golang module for producing and consuming data conforming to these formats. The project's mission is to serve as a unifying, integration format between tools and applications that operate in the security and compliance space. SCI is currently used to model the catalog of compliance controls in the OSPS Baseline and in the FINOS Common Cloud Controls and is expected to be adopted by additional tools like darn/darnit, oscal-tempest, etc.
27+
28+
**_NOTE: due to a naming collision with the existing OpenSSF Supply Chain Integrity WG, if this project is granted Sandbox phase status, it will be renamed._**
2729

2830
### IP policy and licensing due diligence
2931

3032
When contributing an existing Project to the OpenSSF, the contribution must undergo license and IP due diligence by the Linux Foundation (LF).
3133

32-
* SCI is currently licensed under the Apache 2.0 License and requires DCO signoff from all contributors
34+
* Gemera is currently licensed under the Apache 2.0 License and requires DCO signoff from all contributors
3335
* We will initiate this process shortly.
3436

3537
### Project References

0 commit comments

Comments
 (0)