Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

WG Resources #43

Closed
dlorenc opened this issue Dec 13, 2020 · 7 comments
Closed

WG Resources #43

dlorenc opened this issue Dec 13, 2020 · 7 comments

Comments

@dlorenc
Copy link
Contributor

dlorenc commented Dec 13, 2020

Based on @jenniferfernick's comment here: #41 (comment)

I decided to take a quick look at what "resources" WGs are currently using and what they might want/need.

I'm probably missing some, but let's use this as a place to collect a "wishlist" to take to the GB as they consider budgets. We might even be able to get some member companies to kick in help in the meantime. If I missed anything, let me know in the comments and I'll merge back up into this list.

Vulnerability Disclosures

Nothing was obvious from scrolling through the meeting notes/repo.

Security Tooling

The CVE benchmark repo is in a separate GitHub org. It's unclear if this has been properly merged into the OSSF yet, but that's tracked here: #35

Looks like they have some other stuff going on in personal repos/other orgs that might need to be moved over here eventually: (I don't know the actual intent, just guessing based on conversations I skimmed)

Best Practices

Badges

  • Presumably the CII badging program has some infrastructure somewhere, managed and paid for by someone? I assume @david-a-wheeler knows more. The landing page is still at coreinfrastructure.org. Maybe we want to move that to openssf.org at some point?

SKF

  • The SKF Learning platform is running on a bunch of raspberry pis in @blabla1337's house :)
  • They've requested some type of budget for infrastructure to host this. I'm not quite sure on the exact "ownership" of this project, or even what the intent is. It's also listed as part of OWASP in a few places?
  • The repos are under a personal Github[https://github.com/blabla1337/skf-flask)
  • There's a domain (securityknowledgeframework.org)

Scorecards

  • The Scorecards project has a cron that runs every day in a GKE cluster I setup and some text files get published to GCS.

Identifying Security Threats

  • The metrics project appears to be running on Azure somewhere. Probably under @scovetta's account?

Securing Critical Projects

Criticality

This is run manually right now I think, so no real infrastructure. The results got published on GCS, but it's just a few small text files that could easily be moved to anywhere.

Package Feeds

Nothing is really setup here yet. I was going to try running it in a GKE cluster once we get a little farther along.

General Funding

I've funded a few efforts (ISRG, etc.) directly from Google that have presented or asked in these meetings. We'll get a lot more of these requests, and I won't be able to keep up forever. That's working as intented :)

Digital Identity

The main assets here are the awesome presentations hosted on Youtube. I think there's a "round up" blog post coming soon to summarize all of these from Gavin and @kimsterv

There's also talk of a few other whitepapers/publications that could just be hosted out of the repo and linked to from openssf.org.

@kimsterv
Copy link

For existing things that were merged in, there are probably a number of rebranding / marketing exercises we need to go through. For example, CII Badges should be rebranded to OSSF Badges in a number of places.

@david-a-wheeler
Copy link
Contributor

@kimsterv - Rebranding the CII Best Practices badge is totally expected. However, it's also time-consuming & expensive, so it's important that it only happen once. See here for the proposal/discussion on rebranding the CII Best Practices Badge: coreinfrastructure/best-practices-badge#1515 - comments welcome!

@dlorenc
Copy link
Contributor Author

dlorenc commented Dec 15, 2020

We talked about potentially wanting more help with PR/publication for white papers during the vulnerability disclosure meeting today. @MarcinHoppe can add more detail.

@MarcinHoppe
Copy link
Contributor

We are indeed planning to put together a white paper about OSS vulnerability disclosure.

It would be great to know what kind of support we can get from OpenSSF / LF. If we could get assistance or funds for things like graphic design, it would be pretty sweet.

@SecurityCRob
Copy link
Contributor

Hello. As part of 2022 backlog grooming, each open TAC issue is being reviewed for applicability/completeness. Has this request been completed? If so, can that be noted in a comment please. If not, what actions need taken to continue moving this issue to completion? Is this an item that the TAC needs to address in 2022?

If we do not here back from you within two weeks, this issue will be closed (23March2022). Thank you.

@SecurityCRob
Copy link
Contributor

Is this issue still relevant, or will it be covered by 2022 TAC review of WGs?

@SecurityCRob
Copy link
Contributor

No activity in over a year. Closing.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants