devops-automation icon indicating copy to clipboard operation
devops-automation copied to clipboard

open source supply chain WG Meeting March 19, 2024

Open johnmark opened this issue 11 months ago • 6 comments

Date

day-of-week DD MMM yyyy - time EST / time UK

Untracked attendees

Name Firm Comment

Meeting notices

  • FINOS Project leads are responsible for observing the FINOS guidelines for running project meetings. Project maintainers can find additional resources in the FINOS Maintainers Cheatsheet.

  • All participants in FINOS project meetings are subject to the LF Antitrust Policy, the FINOS Community Code of Conduct and all other FINOS policies.

  • FINOS meetings involve participation by industry competitors, and it is the intention of FINOS and the Linux Foundation to conduct all of its activities in accordance with applicable antitrust and competition laws. It is therefore extremely important that attendees adhere to meeting agendas, and be aware of, and not participate in, any activities that are prohibited under applicable US state, federal or foreign antitrust and competition laws. Please contact [email protected] with any questions.

  • FINOS project meetings may be recorded for use solely by the FINOS team for administration purposes. In very limited instances, and with explicit approval, recordings may be made more widely available.

Agenda

  • [ ] Convene, roll call, welcome new people
  • [ ] Approve previous meeting minutes
  • [ ] Review DevOps SIG project board
  • [ ] Package Management
  • [ ] AOB, Q&A & Adjourn (5mins)

Decisions Made

  • [ ] Look into standard for vendors to contribute SBOMs and other supply chain metadata - start with openchain, SPDX, look at gaps - can document provenance and lineage - an incentive for vendors to participate to position their risk mitigation configs. Could potentially provide frameworks and tools to ease the meeting of the standard
  • [ ] Package management - can we approach registries and package management frameworks in a standardized way. Replicating google's assured open source - Karl will reach out to Google rep for Finos. JM will reach out to openchain and SPDX leads
  • [ ] ...

Action Items

  • [ ] Action 1
  • [ ] Action 2
  • [ ] ...

Zoom info

Join Zoom Meeting

  • https://zoom.us/j/94904595244
  • Meeting ID: 949 0459 5244
  • Passcode: 545224
  • Find your local number: https://zoom.us/u/aesEqmNODb

Github Repo: https://github.com/finos/devops-automation/

Project Board: https://github.com/orgs/finos/projects/33

Mailing List: Email [email protected] to subscribe to our mailing list

johnmark avatar Mar 19 '24 12:03 johnmark

Karl Moll / FINOS

karlmoll avatar Mar 19 '24 13:03 karlmoll

JM Walker/Fannie Mae

johnmark avatar Mar 19 '24 13:03 johnmark

amol shukla/morgan stanley

ashukla13 avatar Mar 19 '24 13:03 ashukla13

Alex Ashley / Liatrio

alexashley avatar Mar 19 '24 13:03 alexashley

Ragha Vema | Fannie Mae

rvema avatar Mar 19 '24 13:03 rvema

Eric Chapman - Liatrio

ericchapman80 avatar Mar 19 '24 13:03 ericchapman80