Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 5 additions & 7 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -58,7 +58,6 @@ The following Technical Initiatives have been approved by the TAC. You may learn
| ORBIT (Open Resources for Baselines, Interoperability, and Tooling) | [GitHub](https://github.com/ossf/wg-orbit) | [Meeting Notes](https://docs.google.com/document/d/1Hf-SsjYaAvY2Nk_jJ2-aHMqgBi1qg7oIj3PJWsCEe0U/edit?tab=t.0#heading=h.omyjy2x7t74i) | Jeff Diecks | [Sandbox](process/wg-lifecycle-documents/ORBIT_WG_sandbox_stage.md) |
| Securing Critical Projects | [GitHub](https://github.com/ossf/wg-securing-critical-projects) | [Meeting Notes](https://docs.google.com/document/d/1YkxOFs9x9YCtUfYeOG7Gy3OBX0cTDbZTEgOdvmEo6FE/edit) | Kris Borchers | [Archived](process/wg-lifecycle-documents/archive/securing_critical_projects_archived_stage.md) |
| Securing Software Repositories | [GitHub](https://github.com/ossf/wg-securing-software-repos) | [Meeting Notes](https://docs.google.com/document/d/18Y8HxntL2RkcgqoFdhdLpj17e4MOSCdskP1IoDiuP1s/edit) | Kris Borchers | [Graduated](process/wg-lifecycle-documents/securing_software_repositories_graduation_stage.md) |
| Security Tooling | [GitHub](https://github.com/ossf/wg-security-tooling) | [Meeting Notes](https://docs.google.com/document/d/190urQjwvE6DsjZ3Z1vBbNEXsJ--ccC8xHmbe_fYKRHA/edit) | Jeff Diecks | [Graduated](process/wg-lifecycle-documents/security_tooling_wg_graduation_stage.md) |
| Supply Chain Integrity | [GitHub](https://github.com/ossf/wg-supply-chain-integrity) | [Meeting Notes](https://docs.google.com/document/d/1moVFPn5pLi-uGs840_YBCrwdpHajU0ptFmlL4F9GryQ/edit) | Kris Borchers | Incubating |
| Vulnerability Disclosures | [GitHub](https://github.com/ossf/wg-vulnerability-disclosures) | [Meeting Notes](https://docs.google.com/document/d/1TdxiFofLOfpHUEQILlKq7qkjSsRXVab0uApSDJ8c5rI/edit) | Jeff Diecks | [Graduated](process/wg-lifecycle-documents/Vuln_Disc_wg_graduation_stage.md) |

Expand All @@ -68,11 +67,11 @@ The following Technical Initiatives have been approved by the TAC. You may learn
| Name | Repository | Website | Sponsoring Org | Status |
| ---------------------- | ---------------------------------------- | ----------------------------------------------------------------------------------------------------- | -------------- |---------- |
| Best Practices Badge | [GitHub](https://github.com/coreinfrastructure/best-practices-badge) | https://www.bestpractices.dev/ | Best Practices WG | TBD |
| Bomctl | [GitHub](https://github.com/bomctl/bomctl) | | Security Tooling WG | [Sandbox](process/project-lifecycle-documents/bomctl_sandbox_stage.md) |
| Bomctl | [GitHub](https://github.com/bomctl/bomctl) | | TBD | [Sandbox](process/project-lifecycle-documents/bomctl_sandbox_stage.md) |
| BOMHort | [GitHub](https://github.com/seebom-labs/BOMHort) | https://docs.bomhort.dev/ | WG Supply Chain Integrity | [Sandbox](process/project-lifecycle-documents/BOMHort_sandbox_stage.md) |
| Criticality Score | [GitHub](https://github.com/ossf/criticality_score) | | Vulnerability Disclosures WG | TBD |
| darnit | [GitHub](https://github.com/kusari-oss/darnit) | | Supply Chain Integrity WG | [Sandbox](process/project-lifecycle-documents/darnit_sandbox_stage.md) |
| Fuzz Introspector | [GitHub](https://github.com/ossf/fuzz-introspector) | | Security Tooling WG | TBD |
| Fuzz Introspector | [GitHub](https://github.com/ossf/fuzz-introspector) | | TBD | TBD |
| GUAC | [GitHub](https://github.com/guacsec/guac) | https://guac.sh | Supply Chain Integrity WG | [Incubating](process/project-lifecycle-documents/guac_incubating.md) |
| gittuf | [GitHub](https://github.com/gittuf/gittuf) | https://gittuf.dev/ | Supply Chain Integrity WG | [Incubating](process/project-lifecycle-documents/gittuf_incubating_stage.md) |
| OpenSSF Scorecard | [GitHub](https://github.com/ossf/scorecard) | https://securityscorecards.dev/ | Best Practices WG | [Incubating](process/project-lifecycle-documents/openssf_scorecard_incubating_stage.md) |
Expand All @@ -84,10 +83,10 @@ The following Technical Initiatives have been approved by the TAC. You may learn
| SAFE-Framework | [GitHub](https://github.com/SAFE-MCP/safe-mcp) | | AI/ML Security WG | [Sandbox](process/project-lifecycle-documents/safe_framework_sandbox_stage.md) |
| Package Analysis | [GitHub](https://github.com/ossf/package-analysis) | | Securing Software Repositories WG | TBD |
| Privateer | [GitHub](https://github.com/privateerproj/privateer) | https://privateerproj.com | ORBIT WG | [Sandbox](process/project-lifecycle-documents/Privateer_sandbox_stage.md) |
| Protobom | [GitHub](https://github.com/protobom/protobom) | | Security Tooling WG | [Sandbox](process/project-lifecycle-documents/protobom_sandbox_stage.md) |
| Protobom | [GitHub](https://github.com/protobom/protobom) | | TBD | [Sandbox](process/project-lifecycle-documents/protobom_sandbox_stage.md) |
| Repository Service for TUF | [GitHub](https://github.com/repository-service-tuf/repository-service-tuf) | https://repository-service-tuf.readthedocs.io/ | Securing Software Repositories WG | [Incubating](process/project-lifecycle-documents/repository_service_for_tuf_incubation_stage.md) |
| S2C2F | [GitHub](https://github.com/ossf/s2c2f) | | Supply Chain Integrity WG | [Incubating](process/project-lifecycle-documents/s2c2f_incubation_stage.md) |
| SBOMit | [GitHub](https://github.com/sbomit) | | Security Tooling WG | [Sandbox](process/project-lifecycle-documents/SBOMit_sandbox_stage.md) |
| SBOMit | [GitHub](https://github.com/sbomit) | | TBD | [Sandbox](process/project-lifecycle-documents/SBOMit_sandbox_stage.md) |
| Security Insights Spec | [GitHub](https://github.com/ossf/security-insights-spec) | | ORBIT WG | TBD |
| Sigstore | [GitHub](https://github.com/sigstore) | https://www.sigstore.dev/ | OpenSSF TAC | [Graduated](process/project-lifecycle-documents/sigstore_graduated_stage.md) |
| SLSA | [GitHub](https://github.com/slsa-framework/slsa) | https://slsa.dev/ | Supply Chain Integrity WG | [Graduated](process/project-lifecycle-documents/SLSA_graduation_stage.md) |
Expand All @@ -113,8 +112,7 @@ SIGs can be created and managed without formal approval from the TAC. The follow
| C/C++ Compiler Options | https://github.com/ossf/wg-best-practices-os-developers/tree/main/docs/Compiler-Hardening-Guides | Best Practices WG |
| Python Hardening | https://github.com/ossf/wg-best-practices-os-developers/tree/main/docs/Secure-Coding-Guide-for-Python | Best Practices WG |
| Security Baseline | https://github.com/ossf/security-baseline | ORBIT WG |
| SBOM Everywhere | https://github.com/ossf/sbom-everywhere | Security Tooling WG |
| OSS Fuzzing | https://github.com/ossf/wg-security-tooling?tab=readme-ov-file#oss-fuzzing-sig | Security Tooling WG |
| SBOM Everywhere | https://github.com/ossf/sbom-everywhere | TBD |

### Overview Diagrams

Expand Down
4 changes: 0 additions & 4 deletions organizational-structure-overview.md
Original file line number Diff line number Diff line change
Expand Up @@ -70,7 +70,6 @@ flowchart LR
MM[Metrics & Metadata]
REP[Securing Software Repos]
SCI[Supply Chain Integrity]
ST[Security Tooling]
VD[Vulnerability Disclosures]
end

Expand Down Expand Up @@ -109,9 +108,6 @@ flowchart LR
SCI --> GUAC
SCI --> S2C2F
SCI --> SLSA
ST --> FI
ST --> Protobom
ST --> Sbomit
VD --> CS
VD --> OpenVEX
VD --> OSV
Expand Down
Original file line number Diff line number Diff line change
@@ -1,3 +1,11 @@
## Application for archiving of a Working Group
Comment thread
steiza marked this conversation as resolved.

### Reasons for archiving

The work has stopped because it has completed its chartered deliverables or is no longer progressing on its deliverables as determined by the TAC.

* The Security Tooling WG lead stepped down and the group has not met in 6+ months. There has been no interest from the community for anyone taking over as lead or restoring the WG meetings during this time. The group's projects are without representation for quarterly TAC updates.

## Working Group graduation application

### WG has met all Incubating requirements
Expand Down