Security Tooling WG Archive Application - #644
Conversation
Signed-off-by: Jeff Diecks <55294502+GeauxJD@users.noreply.github.com>
|
Thanks @GeauxJD! On the OpenBao side, we'll use this opportunity to further discuss the matter in the upcoming August TSC call. |
|
I'd prefer finding new homes for the affected projects in new WGs instead of having them report directly to the TAC. The main benefit I see is that being part of a WG fosters intra-WG and cross-project conversations which in turn creates additional value and benefit to those projects. Of course this is subject to mutual agreement between the projects and WGs, i.e., not intending to force anything from the TAC's side (strongly suggesting maybe). |
steiza
left a comment
There was a problem hiding this comment.
Thanks Jeff - I think there's a couple of things to sort out here:
-
Archiving the security tooling WG: this is pretty unambiguous to me, although I think we probably want a standalone
security_tooling_wg_archived_stage.mdinstead of moving thesecurity_tooling_wg_graduation_stage.mddoc -
As for where the projects reporting to the WG should go, I agree that we should work with them to find homes with other WGs. I think the TAC is stretched pretty thin at the moment to oversee additional projects.
Regarding moving the graduation doc, i was following the precedent from the Securing Critical Projects archiving which did the same: https://github.com/ossf/tac/pull/596/changes |
|
My suggestions: |
This PR will require a TAC vote per the WG Lifecycle process.
The TAC will also need to advise on the following projects from this group, as they have not had representation in quarterly updates to the TAC since February 2026:
Options include moving the projects to other working groups such as the proposed SBOM & Vex WG, Supply Chain Integrity WG, etc, or having the projects report directly to the TAC as SigStore does.