Skip to content

Commit

Permalink
update project table and remove qualifier on sigstore status
Browse files Browse the repository at this point in the history
Signed-off-by: Bob Callaway <bcallaway@google.com>
  • Loading branch information
bobcallaway committed Nov 9, 2022
1 parent 79bb654 commit 7f76e02
Show file tree
Hide file tree
Showing 2 changed files with 35 additions and 10 deletions.
24 changes: 19 additions & 5 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -57,11 +57,25 @@ The following Technical Initatives have been approved by the TAC:

### Projects

| Name | Repository | Notes | Status |
| -------------------------- | ------------------- | ----------------------------------------------------------------------------------------------------- | ---------- |
| Sigstore | github.com/sigstore | [Meeting Notes](https://docs.google.com/document/d/1bsl-Y0KulSD7O_nTekad1sAKOVRb80wyGb-Q5x-zdg0/edit) | Incubating |
| GNU Toolchain Improvements | Coming Soon | ? | Incubating |
| Alpha Omega | Coming Soon | ? | Incubating |
| Name | Repository | Notes | Sponsoring Org | Status |
| ---------------------- | ---------------------------------------- | ----------------------------------------------------------------------------------------------------- | -------------- |---------- |
| Allstar | https://github.com/ossf/allstar | [Meeting Notes](https://docs.google.com/document/d/1dB2U7_qZpNW96vtuoG7ShmgKXzIg6R5XT5Tc-0yz6kE/edit#heading=h.4k8ml0qkh7tl) | Best Practices WG | TBD |
| Criticality Score | https://github.com/ossf/criticality_score | [Meeting Notes](https://docs.google.com/document/d/1MIXxadtWsaROpFcJnBtYnQPoyzTCIDhd0IGV8PIV0mQ/edit) | Securing Critical Projects WG | TBD |
| Fuzz Introspector | https://github.com/ossf/fuzz-introspector | [Meeting Notes](https://docs.google.com/document/d/1DoB7zgtLsP-JGF77ASkHV7UMofTE2wseniexaa6Q4M8/edit#) | Security Tooling WG | TBD |
| OSV Schema | https://github.com/ossf/osv-schema | [Meeting Notes](https://docs.google.com/document/d/1mZEi6EvbH2mvn-gHOUIaysAjHlwJXjJdJ7gMlelSkVU/edit#) | Vulnerability Disclosures WG | TBD |
| Package Analysis | https://github.com/ossf/package-analysis | [Meeting Notes](https://docs.google.com/document/d/1MIXxadtWsaROpFcJnBtYnQPoyzTCIDhd0IGV8PIV0mQ/edit) | Securing Critical Projects WG | TBD |
| Package Feeds | https://github.com/ossf/package-feeds | [Meeting Notes](https://docs.google.com/document/d/1MIXxadtWsaROpFcJnBtYnQPoyzTCIDhd0IGV8PIV0mQ/edit) | Securing Critical Projects WG | TBD |
| Scorecard | https://github.com/ossf/scorecard | [Meeting Notes](https://docs.google.com/document/d/1dB2U7_qZpNW96vtuoG7ShmgKXzIg6R5XT5Tc-0yz6kE/edit#heading=h.4k8ml0qkh7tl) | Best Practices WG | TBD |
| Security Insights Spec | https://github.com/ossf/security-insights-spec | [Meeting Notes](https://docs.google.com/document/d/1AfI0S6VjBCO0ZkULCYZGHuzzW8TPqO3zYxRjzmKvUB4/edit?usp=sharing) | Identifying Security Threats WG | TBD |
| Security Metrics | https://github.com/ossf/Project-Security-Metrics | [Meeting Notes](https://docs.google.com/document/d/1AfI0S6VjBCO0ZkULCYZGHuzzW8TPqO3zYxRjzmKvUB4/edit?usp=sharing) | Identifying Security Threats WG | TBD |
| Sigstore | https://github.com/sigstore | [Meeting Notes](https://docs.google.com/document/d/1bsl-Y0KulSD7O_nTekad1sAKOVRb80wyGb-Q5x-zdg0/edit) | OpenSSF TAC | TBD |

### OpenSSF affliated projects

| Name | Repository | Notes | Status |
| -------------------------- | ----------------------------------- | ----- | ------ |
| GNU Toolchain Infrastructure | Coming Soon | TBD | TBD |
| Alpha Omega | https://github.com/ossf/alpha-omega | TBD | TBD |

Charters for these Technical Intiatives are located in the [Charters](charters)
directory of this repository.
Expand Down
21 changes: 16 additions & 5 deletions organizational-structure-overview.md
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ The following table describes the main types of groups and their characteristics

### TODO

* define and document the governance relationships for Alpha/Omega, GNU Toolchain Initiative, and SigStore (collectively, "SIFs")
* define and document the governance relationships for affiliated projects: Alpha/Omega, GNU Toolchain Infrastructure
* define **Contributors** in a consistent way, so that electorate membership can be consistently, and ideally procedurally, determined
* define criteria for approving or disapproving the Charters of TAC-subordinate bodies

Expand All @@ -50,7 +50,7 @@ Legend:

```mermaid
flowchart TB
A([GoverningBoard])
A([Governing Board])
subgraph subC[Committees]
direction TB
Expand All @@ -72,10 +72,21 @@ flowchart TB
ST[Security Tooling]
VD[Vulnerability Disclosures]
ST ---> P2[Scorecards]
SCI ---> P3[SLSA]
BP ---> Allstar[Allstar]
BP ---> Scorecard[Scorecard]
IST ---> SecurityInsights[Security Insights]
IST ---> SecurityMetrics[Security Metrics]
SCI ---> SLSA[SLSA]
SCP ---> CriticalityScore[Criticality Score]
SCP ---> PackageAnalysis[Package Analysis]
SCP ---> PackageFeeds[Package Feeds]
ST ---> FuzzIntrospector[Fuzz Introspector]
VD ---> OSV[OSV Schema]
end
B ====> subWG
B ----> P1[Example Project]
subgraph projects[Projects]
SS[sigstore]
end
B ====> projects
```

0 comments on commit 7f76e02

Please sign in to comment.