CTI TAC Meeting Notes 2025-05-28
Carlos O'Donell <[email protected]> Wed, 28 May 2025 15:59:27 -0400
| Newsgroups | org.linuxfoundation.lists.cti-tac |
|---|---|
| Organization | Red Hat |
| Message-ID | <[email protected]> |
CTI TAC Meeting Notes 2025-05-28
Present:
* Carlos O'Donell
* Joseph Myers
* Kris Borchers (OpenSSF)
* Siddhesh Poyarekar
* David Edelsohn
Agenda:
* [codonell] Both SSDLC docs are posted live.
* Developers asked why not just use a forge? (Comments from Andrew Pinksi)
* co: This doesn't solve all the problems around hosting and supporting it.
* de: Does the forge meeting the project requirements?
* co: No.
* [codonell] Analysis of Sourceware security checklist.
* https://sourceware.org/glibc/wiki/SSDLC/Policy/Sourceware
* [codonell] Noted that we discussed with Kris the meeting with OpenSSF GM. And wanted to have more than one agenda item for a meeting with Steve.
* [kris] Maximizing the value of that meeting would be ideal.
* [codonell] Presented to the OpenSSF TAC on our progress.
* https://github.com/ossf/tac/pull/488 (CY25Q2 status update)
* [siddhesh] It is hard to gather consensus since developers don't want to get involved in a complex conversation.
* [siddhesh] With the SSDLC docs, we have restarted the conversation.
* [codonell] Getting support from specific core developers is important.
* [david] Expanding this conversation beyond the core leadership runs into problems.
* [codonell] Do I need to get all the glibc stewards to respond publicly?
* [david] Is this different from the DCO change?
* [siddhesh] Should we extend this conversation to include Sourceware? How do we extend the conversation to support the security of the projects.
Next steps:
* Carlos to post direct questions to current Sourceware progress.
* Carlos to update the CTI website with current progress.
* Sid to still review OpenSSF best practices badge gold and silver for hardware requirements.
--
Cheers,
Carlos.