Skip to content

Add SCI WG Update for 2026-Q2#614

Open
mlieberman85 wants to merge 1 commit into
ossf:mainfrom
mlieberman85:2026-q2-sci-update
Open

Add SCI WG Update for 2026-Q2#614
mlieberman85 wants to merge 1 commit into
ossf:mainfrom
mlieberman85:2026-q2-sci-update

Conversation

@mlieberman85

Copy link
Copy Markdown
Contributor

Note: I'm waiting on GUAC and Zarf updates

Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
mlieberman85 added a commit to mlieberman85/wg-supply-chain-integrity that referenced this pull request Jun 9, 2026
Repositions the SCI WG as the OpenSSF "maintainer front door" — a
brokering layer that lowers the cost of adopting OpenSSF security
tooling for open-source maintainers. Aligns with Adam Puerco's framing
in the Q2 2026 SCI TAC report (ossf/tac#614) and answers the unmet need
documented in ossf/tac#169.

Mission: "Make adopting OpenSSF security tooling the easy default for
open-source maintainers."

Changes:
- governance/CHARTER.md: full rewrite as v2.0; mission/scope/handoff
  table; lean governance (co-chairs + mailing-list lazy consensus;
  formal TSC deferred as §9.4 TODO); TI admission criteria; §12
  constructive note on broader project↔WG topology; §13 naming
  acknowledgement; §17 TAC ask.
- MAINTAINER-ENABLEMENT.md (new): companion design doc — maintainer
  journey, 10 Y1 deliverables with DRIs and success signals,
  sibling-WG handoff lines, 6/12/24-month metrics, risks, sub-project
  operating model.
- README.md: new mission front-and-center; "Maintainers — start here"
  pointer; Activities → Sponsored Technical Initiatives; Positioning
  SIG link replaced with sunset notice.
- governance/README.md: populated from "TODO"; decision-making and
  amendment process per Charter §9/§16.
- positioning-sig/README.md: sunset notice prepended; history preserved.

No sponsored TI is being moved as part of this charter. Sub-projects
(SLSA, GUAC, gittuf, Zarf, S2C2F, SBOMit, FRSCA, SLSA Tooling) remain
under SCI for now; charter §12 flags the broader topology question to
the TAC as input, not a request.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants