Skip to content

Add missing OpenBao update for 2025Q3 - #637

Open
cipherboy wants to merge 1 commit into
ossf:mainfrom
cipherboy:add-missing-openbao-tac-update
Open

Add missing OpenBao update for 2025Q3#637
cipherboy wants to merge 1 commit into
ossf:mainfrom
cipherboy:add-missing-openbao-tac-update

Conversation

@cipherboy

Copy link
Copy Markdown
Contributor

This was shared with Ryan and was requested in DMs around the time, though never landed in this repository.

See also: #501 (review)
See also: https://gist.github.com/cipherboy/4bb66fe9967fd103a44ea561baaaa4e9/revisions

This was shared with Ryan and was requested in DMs around the time,
though never landed in this repository.

See also: ossf#501 (review)
See also: https://gist.github.com/cipherboy/4bb66fe9967fd103a44ea561baaaa4e9/revisions

Signed-off-by: Alexander Scheel <alex.scheel@control-plane.io>
@cipherboy
cipherboy requested a review from a team as a code owner July 28, 2026 11:08

@karras karras left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thanks!

@lehors lehors left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the report. It is unfortunate that the OpenBAO project apparently uses the term WG for a different type of group that is normally used in OpenSSF. If not too disruptive I would suggest using a different term such as "workstream" just to avoid confusion.

@gkunz gkunz left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for including the missing report.

@cipherboy

cipherboy commented Aug 4, 2026

Copy link
Copy Markdown
Contributor Author

@lehors said:

Thanks for the report. It is unfortunate that the OpenBAO project apparently uses the term WG for a different type of group that is normally used in OpenSSF. If not too disruptive I would suggest using a different term such as "workstream" just to avoid confusion.

Yes, though we started with the term back under LF Edge, where I believe it is more common of an occurrence for projects/initiatives to have working groups, c.f., OpenHorizon (per https://open-horizon.github.io/common-requests/contribute/):

  • Agent Working Group
  • Management Hub Working Group
  • Documentation Working Group

(Developer Examples Working Group is listed elsewhere as well.)

Or EdgeX Foundry (per https://lf-edgexfoundry.atlassian.net/wiki/spaces/FA/pages/11667440/Working+Groups):

  • Technical Working Group
  • Security Working Group

(and many sunset working groups).

At one point someone had suggested SIGs, though I was kinda of the impression that a SIG and a WG had different scopes.

I think workstream is sufficiently close to working group that we could probably adopt it for external references to the TAC. We have mailing lists that I'm not sure if we can rename (e.g., openbao-dev-wg), so it might not fully disappear if adopted. Will propose it to our TSC.

@lehors

lehors commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

@lehors said:

Thanks for the report. It is unfortunate that the OpenBAO project apparently uses the term WG for a different type of group that is normally used in OpenSSF. If not too disruptive I would suggest using a different term such as "workstream" just to avoid confusion.

Yes, though we started with the term back under LF Edge, where I believe it is more common of an occurrence for projects/initiatives to have working groups, c.f., OpenHorizon (per https://open-horizon.github.io/common-requests/contribute/):

I totally understand the history behind it. It is a pet peeve of mine that the Linux Foundation doesn't to a better job at providing new organizations with templates so that we can avoid this kind of accidental variations from one organization to another. Every new org pretty much has to reinvent everything so inevitably we end up with differences that could have easily been avoided.

  • Agent Working Group
  • Management Hub Working Group
  • Documentation Working Group

(Developer Examples Working Group is listed elsewhere as well.)

Or EdgeX Foundry (per https://lf-edgexfoundry.atlassian.net/wiki/spaces/FA/pages/11667440/Working+Groups):

  • Technical Working Group
  • Security Working Group

(and many sunset working groups).

At one point someone had suggested SIGs, though I was kinda of the impression that a SIG and a WG had different scopes.

For its own historical reasons OpenSSF uses SIG and WG (WG above SIGs) in a way that is the opposite in other orgs...

I think workstream is sufficiently close to working group that we could probably adopt it for external references to the TAC. We have mailing lists that I'm not sure if we can rename (e.g., openbao-dev-wg), so it might not fully disappear if adopted. Will propose it to our TSC.

Thanks! Any effort to try and reduce conflicting definitions as much as possible is very much appreciated, even if it's incomplete.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants