Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  1. Waiting for the proposal on scoring guidelines ~ today's meeting will stand cancelled. Meeting agenda will be carried over to 25th Feb.
  2. Question for discussion: signing artefacts policy and reproducible builds.
  3. Policy for dependent license checks.
    1. External agency - Check once a quarter.
  4. Look into score card - from OpenSSF https://github.com/ossf/scorecard .

Action items

  •  Checklist for members to follow while reporting vulnerabilities.
  •  Questionnaire to report vulnerability  ~ calculate CVE score. Danno Ferrin
  •  Define scoring guidelines for blockchain & non-blockchain projects in Hyperledger Foundation. Hart Montgomery

...