Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Community Attendees:

LF Staff:

Agenda

Antitrust Policy

  • Action Items Review

  • Agenda 1

  • Agenda 2

Minutes

Topic 1

  • Comments

Action items

 

  • Kickoff discussion

    • Organisation of work topics

    • Quality goals

    • Security goals

Minutes

Organisation of work topics

  • Olaf Renner proposed to split the work into quality goals and security goals as they are not necessarily related. Depending on the time we need to spend on each we may organise dedicated meetings (alternating?) for one or the other. For both goal areas easy implementation/automation through tools will be critical as otherwise none of these goals will be adopted by projects and manually collecting metrics is just a burden.

Quality Goals

  • Olaf Renner Things like project health review and issues with LFX would fall under this. We had the case that XGVela was defunct for a long time without realising due to missing health reviews.

    • Robert Varga Instead of health reviews shouldn’t this be risk assessment (e.g. of not well governed projects)?

    • Muddasar Ahmed The term we use is not important but we should have the right metrics in place

    • Robert Varga If (new) templates should be used it would be good to see an example. Olaf Renner can start to work on this.

Security Goals

  • Amy Zwarico pointed out that there are security measures that projects should implement like SCA and OpenSFF Badging and some of them can be achieved without major effort

  • Olaf Renner Not all projects have documented their security contacts, or it’s not easy to find (need to search wikis or other documentation). Developers usually start downloading repos and security contacts should be added there.

    • All projects should document their security contacts in the code repo: SECURITY-CONTACTS.md (can link to wiki if project documented the contacts there)

Action items

  •  Amy Zwarico will propose a list of security goals to start with