Skip to content

Security Tooling WG Archive Application - #644

Open
GeauxJD wants to merge 1 commit into
ossf:mainfrom
GeauxJD:archive-tooling-wg
Open

Security Tooling WG Archive Application#644
GeauxJD wants to merge 1 commit into
ossf:mainfrom
GeauxJD:archive-tooling-wg

Conversation

@GeauxJD

@GeauxJD GeauxJD commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

This PR will require a TAC vote per the WG Lifecycle process.

The TAC will also need to advise on the following projects from this group, as they have not had representation in quarterly updates to the TAC since February 2026:

  • bomctl
  • Fuzz Introspector
  • OpenBao
  • Protobom
  • SBOMit

Options include moving the projects to other working groups such as the proposed SBOM & Vex WG, Supply Chain Integrity WG, etc, or having the projects report directly to the TAC as SigStore does.

Signed-off-by: Jeff Diecks <55294502+GeauxJD@users.noreply.github.com>
@GeauxJD
GeauxJD requested a review from a team as a code owner August 14, 2026 20:15
@karras

karras commented Aug 17, 2026

Copy link
Copy Markdown

Thanks @GeauxJD! On the OpenBao side, we'll use this opportunity to further discuss the matter in the upcoming August TSC call.

@gkunz

gkunz commented Aug 18, 2026

Copy link
Copy Markdown
Contributor

I'd prefer finding new homes for the affected projects in new WGs instead of having them report directly to the TAC. The main benefit I see is that being part of a WG fosters intra-WG and cross-project conversations which in turn creates additional value and benefit to those projects. Of course this is subject to mutual agreement between the projects and WGs, i.e., not intending to force anything from the TAC's side (strongly suggesting maybe).

@steiza steiza left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks Jeff - I think there's a couple of things to sort out here:

  1. Archiving the security tooling WG: this is pretty unambiguous to me, although I think we probably want a standalone security_tooling_wg_archived_stage.md instead of moving the security_tooling_wg_graduation_stage.md doc

  2. As for where the projects reporting to the WG should go, I agree that we should work with them to find homes with other WGs. I think the TAC is stretched pretty thin at the moment to oversee additional projects.

@GeauxJD

GeauxJD commented Aug 18, 2026

Copy link
Copy Markdown
Contributor Author

Thanks Jeff - I think there's a couple of things to sort out here:

  1. Archiving the security tooling WG: this is pretty unambiguous to me, although I think we probably want a standalone security_tooling_wg_archived_stage.md instead of moving the security_tooling_wg_graduation_stage.md doc
  2. As for where the projects reporting to the WG should go, I agree that we should work with them to find homes with other WGs. I think the TAC is stretched pretty thin at the moment to oversee additional projects.

Regarding moving the graduation doc, i was following the precedent from the Securing Critical Projects archiving which did the same: https://github.com/ossf/tac/pull/596/changes

@TracyRagan

Copy link
Copy Markdown

My suggestions:
Bomctl, SBOMit and Protobom could fit well into Supply Chain Integrity
Fuzz - possibly Best Practices
OpenBao maybe Orbit??? or TAC directly

@steiza steiza left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM - thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants