glibc status update - Week ending Feb 21st
Carlos O'Donell <[email protected]> Wed, 26 Feb 2025 08:17:04 -0500
| Newsgroups | org.linuxfoundation.lists.cti-tac |
|---|---|
| Organization | Red Hat |
| Message-ID | <[email protected]> |
Current status looks like this:
https://sourceware.org/glibc/wiki/CTI
https://sourceware.org/glibc/wiki/CTI/Policy/glibc
- Reviewed OWASP's SAMM
- It is freely available and useful open standard.
- The process pieces of this standard are too much for the GNU Toolchain.
- The framework is really for a much larger organization starting a program.
- Reviewed Black Duck's BSIMM
- Could not review data since BSIMM is a live standard.
- You need an assesor to compare you to the industry baseline.
- We naturally compare solutions across FOSS so this standard
doesn't really apply to provide a checkbox certification.
- Updated main page justification for why we're using NIST SP 800-218.
- Noted references for all the other standards.
- Noted that we follow NISTS framework because it is a useful framework.
Next week
- Start writing glibc position.
--
Cheers,
Carlos.