3 ms·
This is a fascinating peek into the unglamourous administrative moving parts of supply chain risk management. Octave [0], Cygwin [1] and GIMP [2] mailing lists
by __jf__ 6y ago
This is a fascinating peek into the unglamourous administrative moving parts of supply chain risk management.
Octave [0], Cygwin [1] and GIMP [2] mailing lists were also fortunate enough to be included in this process. Given the timespan between the posts this seems to be taken rather seriously.
I also found the likely reason in [3]: since 2019 they have a new supply chain risk management proces. Slide 10 gives some additional background.
[0] https://octave.1599824.n4.nabble.com/Country-of-Origin-Verification-3144-td4696407.html https://octave.1599824.n4.nabble.com/Country-of-Origin-Verif...
[1] http://cygwin.1069669.n5.nabble.com/Country-Of-Origin-Verification-8944-td152055.html http://cygwin.1069669.n5.nabble.com/Country-Of-Origin-Verifi...
[2] https://www.talkend.net/post/75432.html https://www.talkend.net/post/75432.html
[3] https://csrc.nist.gov/CSRC/media/Projects/cyber-supply-chain-risk-management/documents/SSCA/Spring_2019/9MayAM1.2_NASA_SSCA_May_9th.pdf https://csrc.nist.gov/CSRC/media/Projects/cyber-supply-chain...