wg-securing-critical-projects icon indicating copy to clipboard operation
wg-securing-critical-projects copied to clipboard

Adopt "Census I" as an archived Project/SIG under this WG

Open jeffmendoza opened this issue 9 months ago • 7 comments

I have an odd request. I'd like to merge an archived project now called "census I" into this WG, keeping it archived. The reason is that I think it's important to continue to make it available.

Years ago I led a project to measure criticality, now often called "Census I". The report & supporting code are currently here: https://github.com/coreinfrastructure/census Interestingly enough, that report specifically noted the xz utility as especially concerning. Given the effort recently to insert a backdoor into xz, that seems prescient.

However, the coreinfrastructure (CII) project is no longer in existence, and in the long term we want to remove projects from it.

I think it's important for the OpenSSF to include this repository so that future work can easily refer to it.

Seem reasonable?

Please vote on this proposal below

jeffmendoza avatar May 23 '24 15:05 jeffmendoza