COMING TOMORROW: OpenChain Monthly North America / Asia call - 2023-03-21 09:00 CST / 10:00 KST+JST (01:00 UTC)


 

Dear All

A reminder that our monthly North America / Asia call is taking place tomorrow, 2023-03-21, at 09:00 CST / 10:00 KST+JST (01:00 UTC). That will be 18:00 Pacific on the 20th of March for our colleagues in North America. Calendar invite attached.

We are editing the next generation license compliance and security assurance specifications. On the North America / Europe call earlier this month we opened a new discussion on:

Comments on the Known Vulnerability in the proposed Security Assurance Specification:
https://github.com/OpenChain-Project/Security-Assurance-Specification/issues/19

We recapped / reviewed:

Please add definitions for “remediate” and “mitigate”:
https://github.com/OpenChain-Project/Security-Assurance-Specification/issues/22

Under the Competence category, add requirements#23:
https://github.com/OpenChain-Project/Security-Assurance-Specification/issues/23

Add references to ISO/IEC Standards:
https://github.com/OpenChain-Project/Security-Assurance-Specification/issues/24

We also opened this new issue:

Add triage entry to specific situations where vulnerability not applicable:
https://github.com/OpenChain-Project/Security-Assurance-Specification/issues/29

We have the following items pending for *this* call:

= Security =

We will return to…

Add triage entry to specific situations where vulnerability not applicable:
https://github.com/OpenChain-Project/Security-Assurance-Specification/issues/29

Comments on the Known Vulnerability in the proposed Security Assurance Specification:
https://github.com/OpenChain-Project/Security-Assurance-Specification/issues/19

+

Add program objectives
https://github.com/OpenChain-Project/Security-Assurance-Specification/issues/14

Clarify Stated Purpose (Github) and Scope (specification):
https://github.com/OpenChain-Project/Security-Assurance-Specification/issues/28

= Licensing =

Consider adding definition of 'bill of materials’
https://github.com/OpenChain-Project/License-Compliance-Specification/issues/35

Move "Access" to be part of "Compliance Artifact Delivery”
https://github.com/OpenChain-Project/License-Compliance-Specification/issues/53

I look forward to seeing you at:
https://zoom.us/j/4377592799

Regards

Shane

Join main@lists.openchainproject.org to automatically receive all group messages.