diff --git a/README.md b/README.md index 04de2e9e..444424bc 100644 --- a/README.md +++ b/README.md @@ -56,7 +56,7 @@ The following Technical Initiatives have been approved by the TAC. You may learn | Security Tooling | https://github.com/ossf/wg-security-tooling | [Meeting Notes](https://docs.google.com/document/d/1jzxhzIfkOMTagpeFWYoZpMKwHYeO4Gc7Eq5FcMFEw2c/edit#heading=h.wdz394z3k3h2) | Incubating | | Security Best Practices | https://github.com/ossf/wg-best-practices-os-developers | [Meeting Notes](https://github.com/ossf/wg-best-practices-os-developers/blob/main/meeting-minutes.md) | [Graduated](process/wg-lifecycle-documents/BEST_practices_wg_graduation_stage.md) | | Metrics & Metadata | https://github.com/ossf/wg-metrics-and-metadata | [Meeting Notes](https://docs.google.com/document/d/14_ILDhSK3ymKqUTQeQBRgJKgfiy_ePoGZIe8s7p3K5E/edit) | Incubating | -| Securing Critical Projects | https://github.com/ossf/wg-securing-critical-projects | [Meeting Notes](https://docs.google.com/document/d/1GFslP6elYCx27TUitdigDr1gsOItYkL0Vq7hTB9y4Lo/edit) | Incubating | +| Securing Critical Projects | https://github.com/ossf/wg-securing-critical-projects | [Meeting Notes](https://docs.google.com/document/d/1GFslP6elYCx27TUitdigDr1gsOItYkL0Vq7hTB9y4Lo/edit) | [Incubating](process/wg-lifecycle-documents/securing_critical_projects_incubating_stage.md) | | Supply Chain Integrity | https://github.com/ossf/wg-supply-chain-integrity | [Meeting Notes](https://docs.google.com/document/d/1xPs2sSbH3I9Ich7OyLOzl85oJshnK8Q6WoAgREE5-zA/edit) | Incubating | | Securing Software Repositories | https://github.com/ossf/wg-securing-software-repos | [Meeting Notes](https://docs.google.com/document/d/1-f6m442MHg9hktrbcp-4sM9GbZC3HLTpZPpxMXjMCp4/edit) | [Graduated](process/wg-lifecycle-documents/Securing_software_repositories_graduation_stage.md) | | End Users | https://github.com/ossf/wg-endusers | [Meeting Notes](https://docs.google.com/document/d/1abI65H4pF5y8YtA2_TuDBAaI47v9mTfpr5mwVvccX_I/edit) | Incubating | diff --git a/process/wg-lifecycle-documents/securing_critical_projects_incubating_stage.md b/process/wg-lifecycle-documents/securing_critical_projects_incubating_stage.md new file mode 100644 index 00000000..1c165e6b --- /dev/null +++ b/process/wg-lifecycle-documents/securing_critical_projects_incubating_stage.md @@ -0,0 +1,60 @@ +## Securing Critical Projects Working Group incubation application + +### List WG Chair(s) and or Vice Chair + +The WG must have a minimum of 1 Chair + +* "Amir Montazery, Open Source Technology Improvement Fund, Inc, Amir-Montazery" +* "Jeff Mendoza, Kusari, Inc, jeffmendoza" + +### Working Group (WG) has met all Sandbox requirement + +* Applying directly to Incubating + +### List of regular contributors + +The WG must have a minimum of 5 contributors from at least 3 different +organizations attending regularly. + +* Jeff Mendoza, Kusari +* Amir Montazery, Open Source Technology Improvement Fund, Inc +* Caleb Brown, Google +* David Edelsohn, IBM +* David C Stewart, Intel +* David A. Wheeler, LF +* Randall T. Vásquez, Gentoo/Homebrew/SKF +* Yotam Perkal, Rezilion + +### Mission of the Working Group + +The WG must have a charter or mission statement for review by TAC + +* https://github.com/ossf/wg-securing-critical-projects/blob/main/MVSR.md + +### Governance + +WG must have documented, initial group governance. + +* https://github.com/ossf/wg-securing-critical-projects/blob/main/CHARTER.md + +WG must have met publicly at least 5 times in the last quarter since becoming +Sandbox + +* 2024: https://docs.google.com/document/d/1j_efLVDXGoKgfHHZbJtpBxd_Gso1ghHBdK3NfEVc15o/edit?usp=sharing +* 2020-2023: https://docs.google.com/document/d/1GFslP6elYCx27TUitdigDr1gsOItYkL0Vq7hTB9y4Lo/edit#heading=h.n1an2kl9m54e +* https://www.youtube.com/playlist?list=PLVl2hFL_zAh-cAfx6y4k-fODfbHeQzb_O + +WG must have defined Contributor Guide + +* https://github.com/ossf/wg-securing-critical-projects?tab=readme-ov-file#operations + + Reference | URL | +|-----------------------|-----| +| Repo | https://github.com/ossf/wg-securing-critical-projects | +| Meeting Agenda | https://docs.google.com/document/d/1j_efLVDXGoKgfHHZbJtpBxd_Gso1ghHBdK3NfEVc15o/edit?usp=sharing | +| OSSF Calendar Entry | https://www.google.com/calendar/event?eid=MmpuZGJiZjBvaGpqMXVuOGNpYW1jMjgyOGZfMjAyNDA1MjNUMTYwMDAwWiBzNjN2b2VmaHA1aTlwZmx0YjVxNjduZ3Blc0Bn&ctz=America/New_York | +| Website | | +| Contributing guide | https://github.com/ossf/wg-securing-critical-projects?tab=readme-ov-file#operations | +| Security.md | https://github.com/ossf/wg-securing-critical-projects/blob/main/SECURITY.md | +| code-of-conduct.md | https://github.com/ossf/wg-securing-critical-projects/blob/main/code-of-conduct.md | +| Other | |