CTI TAC Meeting Notes 2024-10-30
Carlos O'Donell <[email protected]> Wed, 30 Oct 2024 11:59:26 -0400
| Newsgroups | org.linuxfoundation.lists.cti-tac |
|---|---|
| Organization | Red Hat |
| Message-ID | <[email protected]> |
CTI TAC Meeting Notes 2024-10-30 Present: * Carlos O'Donell * Joseph Myers * David Edelsohn * Siddhesh Poyarekar * Adrianne Marcum (OpenSSF) * Kris Borchers (OpenSSF) Agenda: * Carlos: Posted CY24Q3 update. * https://lore.kernel.org/cti-tac/[email protected]/ * David: The requirements from various governments, business partners, that these are requirements coming down from upcoming regulations. * Carlos: Present my current view of NIST SP 800-218 and certain steps where we align and where we don't. * Carlos: Look at OpenSSF best practices badge and requirements for where we align or don't align with the current infrastructure. * Introduction from Kris Borchers (OpenSSF). Experience with several other foundations. * Carlos: Added Kris to the official calendar invite. * Carlos: Asking Joseph if this layout meets the requirements raised at the previous TAC meeting to call out specific standards and page and item references. * Joseph: Yes, but presumable focused on the systems related to CTI and CTIs scope. * Carlos: Agreed, but I'm starting by telling a story that SSDF has many reasonable requirements, some which we meet with community process, but then move on to the other requirements. * Siddhesh: Definitely need a table. Focus should be a structured table. * Carlos: Concern that for entries that are contentious * Siddhesh: C++ Compiler Flag guide that the OpenSSF publishes is a structure we could borrow from? What about things that Sourceware cannot provide? * Carlos: Noting here https://github.com/ossf/wg-best-practices-os-developers/blob/main/docs/Compiler-Hardening-Guides/Compiler-Options-Hardening-Guide-for-C-and-C%2B%2B.md for reference. * Carlos: I'll use the structure of this for the document with a table on top. * Carlos: I have a note from downstream that the LLVM Foundation and developers in the organization are pusuing a review of best practices from the OpenSSF. We can do the same? * Carlos: Which is the best practices badge for OpenSSF that has silver and gold? * David: https://www.bestpractices.dev/en/projects/5321 * David: Each criteria is at a given level, particularly silver and gold. * Next steps: * AI: Carlos to complete and publisize the glibc notes about specific NIST SSDF steps. * AI: Siddhesh to look at GCC and OpenSSF Best Practices badge and infrastructure requirements. -- Cheers, Carlos.