CTI TAC Meeting Notes 2024-10-30

Carlos O'Donell <[email protected]> Wed, 30 Oct 2024 11:59:26 -0400
Newsgroups org.linuxfoundation.lists.cti-tac
Organization Red Hat
Message-ID <[email protected]>
​CTI TAC Meeting Notes 2024-10-30

Present:
 * Carlos O'Donell
 * Joseph Myers
 * David Edelsohn
 * Siddhesh Poyarekar
 * Adrianne Marcum (OpenSSF)
 * Kris Borchers (OpenSSF)
 
Agenda:
 * Carlos: Posted CY24Q3 update.
  * https://lore.kernel.org/cti-tac/[email protected]/
  * David: The requirements from various governments, business partners, that these are requirements coming down from upcoming regulations.
 * Carlos: Present my current view of NIST SP 800-218 and certain steps where we align and where we don't.
 * Carlos: Look at OpenSSF best practices badge and requirements for where we align or don't align with the current infrastructure.
 * Introduction from Kris Borchers (OpenSSF). Experience with several other foundations.
 * Carlos: Added Kris to the official calendar invite.
 * Carlos: Asking Joseph if this layout meets the requirements raised at the previous TAC meeting to call out specific standards and page and item references.
 * Joseph: Yes, but presumable focused on the systems related to CTI and CTIs scope.
 * Carlos: Agreed, but I'm starting by telling a story that SSDF has many reasonable requirements, some which we meet with community process, but then move on to the other requirements.
  * Siddhesh: Definitely need a table. Focus should be a structured table.
 * Carlos: Concern that for entries that are contentious
 * Siddhesh: C++ Compiler Flag guide that the OpenSSF publishes is a structure we could borrow from? What about things that Sourceware cannot provide?
 * Carlos: Noting here https://github.com/ossf/wg-best-practices-os-developers/blob/main/docs/Compiler-Hardening-Guides/Compiler-Options-Hardening-Guide-for-C-and-C%2B%2B.md for reference.
 * Carlos: I'll use the structure of this for the document with a table on top.
 * Carlos: I have a note from downstream that the LLVM Foundation and developers in the organization are pusuing a review of best practices from the OpenSSF. We can do the same?
 * Carlos: Which is the best practices badge for OpenSSF that has silver and gold?
 * David: https://www.bestpractices.dev/en/projects/5321
 * David: Each criteria is at a given level, particularly silver and gold.
 * Next steps:
      * AI: Carlos to complete and publisize the glibc notes about specific NIST SSDF steps.
      * AI: Siddhesh to look at GCC and OpenSSF Best Practices badge and infrastructure requirements.

-- 
Cheers,
Carlos.