-
Notifications
You must be signed in to change notification settings - Fork 226
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Transfer image-attestation demo to slsa-framework org #1110
Comments
CC @slsa-framework/slsa-steering-committee @slsa-framework/specification-maintainers |
I think that's great and I'm supportive of this move. However I'm afraid this raises some question of IP transfer that may require proper clearance involving the OpenSSF staff. |
Pinging @Naomi-Wash for the question about IP transfer here. |
Is there still an IP concern even if the repo has an MIT license? |
Unfortunately the license is necessary but not quite sufficient. You can see what kind of things OpenSSF looks at when importing projects in the just posted bomctl report. |
Hello everyone - we're following up with the LF IP manager and hope to have some guidance for you this week. (cc @riaankleinhans) |
@Naomi-Wash @riaankleinhans Has there been an update from the LF IP manager on this transfer? |
@marcelamelara we didn't see any concerns, but legal is double-checking just in case. Sorry for the delay. Hoping to have this wrapped up by EOW. |
Great, thank you @Naomi-Wash ! |
Hello everyone, please forgive the delay on this. I heard back from legal and this is their advice. @chkimes please check this project into a SLSA repository. It looks like any other contribution and should go through the same process. You can do a PR for this entire repo into the SLSA org. Sorry again for the delay! |
Hi @Naomi-Wash, thanks so much for the update! |
Could someone create an |
@chkimes there's two simple options here:
|
I can't transfer without permissions to create repos. The forking route can work, or I can create a PR to an empty repo that someone else creates in the org. |
@chkimes It looks like I have permission to create a new repo, I'll go do that now. |
@chkimes Can you please open a PR at https://github.com/slsa-framework/attested-build-environments-demo |
@marcelamelara can you push a commit with |
@chkimes done! |
The workstream for HW Attested Build Environments has been building a POC in a repo under my user account: https://github.com/chkimes/image-attestation. We would like to move this under the SLSA framework GitHub org to more accurately reflect the shared ownership of the POC implementation.
cc @paveliak @marcelamelara
The text was updated successfully, but these errors were encountered: