Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add Alpha-Omega Q4 Update #410

Open
wants to merge 2 commits into
base: main
Choose a base branch
from
Open

Add Alpha-Omega Q4 Update #410

wants to merge 2 commits into from

Conversation

scovetta
Copy link
Contributor

No description provided.

Signed-off-by: Michael Scovetta <[email protected]>
@scovetta scovetta requested a review from a team as a code owner November 11, 2024 02:30

Some key opportunities to engage:

* Our next monthly report is due out around July 5th.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's hard to follow the timeline in this section. It's unclear if this is part of a previous update that wasn't merged or if this section is incorrect.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @mlieberman85, copy-paste error from Q2, fixed.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good now!

Signed-off-by: Michael Scovetta <[email protected]>
Copy link
Contributor

@mlieberman85 mlieberman85 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lgtm

Copy link
Contributor

@lehors lehors left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks.

Copy link
Member

@steiza steiza left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great updated - thank you!

@marcelamelara marcelamelara added the TI Update Quarterly TI update. Needs 5 approvals, 7d review. label Nov 20, 2024
Copy link
Contributor

@marcelamelara marcelamelara left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks so much for the update @scovetta ! I left a couple of discussion questions :)

discussing next steps, and will share details when we're able to.

* **Engagement**: We recently expanded our engagement with Node.js to cover OpenJS, started an engagement with
Trail of Bits of improve PyPI's project-level lifecycle functionality, and kicked off a new type of engagement ("Beach Cleaning")
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

small typo

Suggested change
Trail of Bits of improve PyPI's project-level lifecycle functionality, and kicked off a new type of engagement ("Beach Cleaning")
Trail of Bits to improve PyPI's project-level lifecycle functionality, and kicked off a new type of engagement ("Beach Cleaning")

|**O2: The top 10,000 open source projects are free of critical security vulnerabilities**||
|KR 2.1: Drive adoption of key security processes, including static analysis, credential scanning, the use of private vulnerability disclosures, structured metadata (Security Insights) and the use of multi-factor authentication by maintainers of 500 critical projects from the top 10,000 by the end of 2024.|Not Started|
|KR 2.2: Independently scan, triage, and notify maintainers when critical vulnerabilities are found in 2,000 projects, chosen from the top 10,000 by the end of June 2024, with emphasis on clearing a "section of the beach" by focusing on the top PyPI packages.|On target|
|KR 2.3: Publish in a machine readable format the attestations for all packages from 2.2 that returned no vulnerabilities and those that found vulnerabilities which were subsequently fixed and verified.|On target|
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is more out of curiosity: What's the format you're using for these attestations? Is it in-toto, or some other format?


## Additional Information

Here's a selection of recent news and blogs referring to Alpha-Omega's work and impact:
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I really appreciate this list!

We'll be at the Linux Foundation Member Summit next week, sponsoring a Happy Hour for OpenSSF Governing Board and TAC
on 11/17 from 5-6 PM at the Mansion Bar & Terrace (at the Silverado Resort). We hope to see you there.

We continue to hold monthly public meetings (on the OpenSSF community calendar).
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

How well attended are these meetings, i.e., how many folks beyond the core team attend regularly?

We've received $5M in funding in 2024 and are on target to spend over $6M by the end of the year.


### Up Next
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Were there any actionable next steps coming out of the roundtable in Vienna? If yes, I think it'd be great to note those here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
TI Update Quarterly TI update. Needs 5 approvals, 7d review.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

6 participants