CTI TAC Meeting Notes 2025-01-29

Carlos O'Donell <[email protected]> Wed, 29 Jan 2025 11:45:48 -0500
Newsgroups org.linuxfoundation.lists.cti-tac
Organization Red Hat
Message-ID <[email protected]>
​CTI TAC Meeting Notes 2025-01-29

Present:
 * Carlos O'Donell, Joseph Myers, Siddhesh Poyarekar.
 * Kris Borchers (OpenSSF), sends regrets since he can't sign in.

 Agenda:
 * Carlos: Still writing updates for the glibc community.
  * https://sourceware.org/glibc/wiki/CTI
  * https://sourceware.org/glibc/wiki/CTI/Policy/glibc
 * Carlos: Change in strategy. I didn't make enough process in December and January to publish my document and glibc policy. I'm going to switch to doing a weekly report to the CTI TAC mailing list with my updates to drive the completion of the document by end of February. Strategy going forward is walking the NIST SP-800-218 items (~14 pages) in order and identifying the glibc policy, how Sourceware does or does not meet that, and how CTI would meet that.
 * Carlos: The lynch pin in the argument is that we are doing this because we want to show FOSS can and will support the security and safety requirements of all users, including downstream distributions.
 * Carlos: Tracking NIST SP-800-218 page references in the document for anyone following along, but providing rewritten language that is more developer friendly.
 * Siddhesh: Discuss best practices badge for OpenSSF.
  * Carlos: There are some "Met" statements in the PASSING badge that are hand waved. Particularly around static analysis for each release.
  * Carlos: To limit scope my question from the previous meeting was limited to evaluating the infrastructure requirements from the OpenSSF best practices passing, silver and gold levels. For example Eclipse foundation requires 2FA.
 * Joseph: Discuss the experimental Forge and forge-like services and the potential security characteristics of the forge?
  * Carlos: Can I do this last? I'm prioritizing what we do today.
  * Joseph: Yes, this is a future option for development that would need to be evaluted.
 * No further requests from the CTI TAC to CTI board or the OpenSSF.
 
Next steps
 * Siddhesh to go check silver and gold best practices badge levels and report on infrastructure requirements.
 * Carlos to start posting weekly updates about the writeup, with the goal to complete in February and publish a CTI update for the first quarter with that text. Working through 14-15 pages of the practices and tasks.
 * CY25Q1 udpate posted with glibc notes about policy and why we want to meet that policy.

-- 
Cheers,
Carlos.