Skip to content

Conversation

@gkunz
Copy link
Contributor

@gkunz gkunz commented Jan 16, 2026

No description provided.

Signed-off-by: Georg Kunz <georg.kunz@ericsson.com>
Copy link
Member

@steiza steiza left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the update! A few minor questions about links, service funding, and Scorecard checks.

Comment on lines 10 to 11
* [C/C++ Compiler Option Hardening](https://github.com/ossf/tac/diffs/0?base_sha=eed2ae23a0d8a2e5b18d9bcdeeb7fa40b75ac241&branch=87769be64cb25d5808e856910370771544fbe4e6&commentable=true&head_user=gkunz&name=87769be64cb25d5808e856910370771544fbe4e6&pull_number=423&qualified_name=87769be64cb25d5808e856910370771544fbe4e6&sha1=eed2ae23a0d8a2e5b18d9bcdeeb7fa40b75ac241&sha2=87769be64cb25d5808e856910370771544fbe4e6&short_path=409950f&unchanged=expanded&w=false#cc-compiler-option-hardening-guide)
* [Python Secure Coding Guide](https://github.com/ossf/tac/diffs/0?base_sha=eed2ae23a0d8a2e5b18d9bcdeeb7fa40b75ac241&branch=87769be64cb25d5808e856910370771544fbe4e6&commentable=true&head_user=gkunz&name=87769be64cb25d5808e856910370771544fbe4e6&pull_number=423&qualified_name=87769be64cb25d5808e856910370771544fbe4e6&sha1=eed2ae23a0d8a2e5b18d9bcdeeb7fa40b75ac241&sha2=87769be64cb25d5808e856910370771544fbe4e6&short_path=409950f&unchanged=expanded&w=false#python-secure-coding-guide)
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These links don't work for me - they seem to be in the ossf/tac repo?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry, not sure what happened here. I'll replace the broken links with proper ones.


* The Open Source Security Foundation (OpenSSF) Best Practices badge is a way for Free/Libre and Open Source Software (FLOSS) projects to show that they follow best practices. Projects can voluntarily self-certify, at no cost, by using this web application to explain how they follow each best practice.

#### **Status Update**
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In the meeting, should we talk a little bit about the Best Practices service and how it's being funded?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't actually know the details. @david-a-wheeler would be the best person to elaborate on this.


* Discussions with the TAC and OpenSSF staff ongoing regarding funding of hosted services.
* Scorecard audit completed: [https://openssf.org/blog/2025/10/10/openssf-scorecard-audit-is-complete/](https://openssf.org/blog/2025/10/10/openssf-scorecard-audit-is-complete/)
* Work on new checks is ongoing
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This might be a question for the Scorecard project directly, but do we have a sense on if there's plans in 2026 to revisit some of the checks from 2020 based on community feedback? In particular the critical / high risk checks, like:

Signed-off-by: Georg Kunz <georg.kunz@ericsson.com>
@gkunz gkunz added the TI Update Quarterly TI update. Needs 5 approvals, 7d review. label Jan 20, 2026

#### **Up Next**

* Continue working on roadmap \+ funding situation
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

At the risk of sounding like a broken record I have to say again that I hope the roadmap will include exploring how Scorecard can integrate with the BP badge.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

TI Update Quarterly TI update. Needs 5 approvals, 7d review.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants