wg-securing-critical-projects
wg-securing-critical-projects copied to clipboard
Adopt "Census I" as an archived Project/SIG under this WG
I have an odd request. I'd like to merge an archived project now called "census I" into this WG, keeping it archived. The reason is that I think it's important to continue to make it available.
Years ago I led a project to measure criticality, now often called "Census I". The report & supporting code are currently here: https://github.com/coreinfrastructure/census Interestingly enough, that report specifically noted the xz utility as especially concerning. Given the effort recently to insert a backdoor into xz, that seems prescient.
However, the coreinfrastructure (CII) project is no longer in existence, and in the long term we want to remove projects from it.
I think it's important for the OpenSSF to include this repository so that future work can easily refer to it.
Seem reasonable?
Please vote on this proposal below