-
Notifications
You must be signed in to change notification settings - Fork 84
CY26Q3 update for Core Toolchain Infrastructure Project #646
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
codonell
wants to merge
1
commit into
ossf:main
Choose a base branch
from
codonell:CTI-CY26Q3
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Changes from all commits
Commits
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,83 @@ | ||
| # 2026 Q3 Core Toolchain Infrastructure Project (CTI) | ||
|
|
||
| ## Overview | ||
|
|
||
| Core Toolchain Infrastructure Project (CTI) continues to work towards providing state of the art secure infrastructure for the GNU Toolchain and ancillary projects. | ||
|
|
||
| In CY26Q3 the work continues to focus on supporting the GNU C Library (one of 4 core GNU Toolchain projects) to migrate services to CTI. | ||
|
|
||
| Since CY26Q2 the project has continued to hold weekly Friday office hours and completed the following: | ||
|
|
||
| * Created CTI service transition plan for glibc and started hashing out the details: | ||
| * https://sourceware.org/glibc/wiki/service-transition-plan | ||
| * https://sourceware.org/glibc/wiki/after-transition-steps | ||
| * https://sourceware.org/bugzilla/show_bug.cgi?id=34384 | ||
| * https://inbox.sourceware.org/libc-alpha/eb4a8c7c-50fc-46fe-aed3-5b8834284f2d@redhat.com/ | ||
| * Met twice with LF IT during Office Hours for CTI to discuss the SOW and work items. | ||
| * LF IT joining #cti-help on OFTC to discuss specific items in realtime. | ||
| * Continued engaging with 4 sponsors for CY27 and CY28 funding. | ||
| * Identified 1 sponsor that needs a pitch deck and information sent to. | ||
| * Identified 12 other sponsors which we need to follow up with regarding funding and contacts. | ||
|
|
||
| The CTI TAC is working closely with developers to transition smoothly to the modern infrastructure for `git` and email. Once this transition is in progress we will continue to review other services and projects in the GNU Toolchain (gcc, binutils and gdb). | ||
|
|
||
| ## Core Toolchain Infrastructure Project | ||
|
|
||
| Core Toolchain Infrastructure Project (CTI) in 2026 Q3 continues to move forward secure development practices, but now in direct support for the GNU C Library (glibc) as the first GNU Toolchain project to migrate to new CTI services. | ||
|
|
||
| In order to engage the developers and discuss the transition the CTI TAC continues to hold weekly Friday office hours for the migration. | ||
|
|
||
| ### Purpose | ||
|
|
||
| The Core Toolchain Infrastructure (CTI) Project’s mission is to support the GNU Toolchain community with secure infrastructure and state of the art services required to support the community’s development efforts to be a trusted foundation in a secure supply chain. | ||
|
|
||
| The CTI project continues to move forward the goal of creating a long-term sustainable set of secure and state of the art services and infrastructure for the GNU Toolchain and related packages. | ||
|
|
||
| Some of the major goals include: | ||
|
|
||
| * Secure and state of the art infrastructure. | ||
| * Continuity planning for infrastructure, development, and governance. | ||
| * Security policy planning. | ||
|
|
||
| ### MVSR | ||
|
|
||
| Mission: | ||
|
|
||
| * To support the GNU Toolchain community with secure infrastructure and state of the art services required to support the community’s development efforts to be a trusted foundation in a secure supply chain. | ||
|
|
||
| Vision: | ||
|
|
||
| * A thriving ecosystem of software that can be developed with the GNU Toolchain as a trusted foundation in a secure supply chain. | ||
|
|
||
| Strategy: | ||
|
|
||
| * Review, prioritize, and support key infrastructure requirements from the GNU Toolchain community in collaboration with project sponsors. | ||
|
|
||
| Roadmap: | ||
|
|
||
| * Establish a baseline of secured services with support from project sponsors. | ||
|
|
||
| ### Current Status | ||
|
|
||
| * Working with Linux Foundation IT to design a transition plan for August to December 2026. | ||
|
|
||
| ### Up Next | ||
|
|
||
| * Finalize glibc transition plan and dates with community, Sourceware.org and LF IT. | ||
| * Engage an additional 4 sponsors (of the 12 identified) in CY26Q3-Q4 for CY27 and CY28. | ||
|
|
||
| ### Funding requests and updates | ||
|
|
||
| The Core Toolchain Infrastructure project as a Linux Foundation ADF was already granted funding and has been using this funding to support the service transition. | ||
|
|
||
| The remaining funding for CTI will be spent in CY26Q3-Q4 to transition the glibc services to CTI. | ||
|
|
||
| Sponsors for CTI are directed to email the TAC at cti-tac@lists.linuxfoundation.org, or to directly review the ADF (https://enrollment.lfx.linuxfoundation.org/?project=cti). | ||
|
|
||
| ### Questions/Issues for the TAC | ||
|
|
||
| None at this time. | ||
|
|
||
| ## Additional Information | ||
|
|
||
| No additional information noted for CY26Q3. | ||
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Just an observation: I am getting 429's for these links