4 ms·
For what it's worth, I reached out to the Open Source Security Foundation (OpenSSF) after their press release on "Securing Critical Open Source Projects" [0], b
by Radim 6y ago
For what it's worth, I reached out to the Open Source Security Foundation (OpenSSF) after their press release on "Securing Critical Open Source Projects" [0], because my open source project is on their "critical list" (Python top #200) [1].
After some clicking around, I was directed to the OpenSSF mailing list [2].
…where my request was left to rot, without any response.
Made me wonder whether this is just a PR stunt / corporate power grab.
[0] https://opensource.googleblog.com/2020/12/finding-critical-open-source-projects.html https://opensource.googleblog.com/2020/12/finding-critical-o...
[1] https://news.ycombinator.com/item?id=25381397 https://news.ycombinator.com/item?id=25381397
[2] https://groups.google.com/g/wg-securing-critical-projects https://groups.google.com/g/wg-securing-critical-projects
- ZebusJesus 6y agoI think it is, the maintainers of curl even talked about how C is a secure language and how curl is on almost every system possible which is why it has flaws, not because C is insecure. Debugging your code on almost every hardware out there is not possible which is why it is open source and why they intended you to adapt it not just run it
- twic 6y agoI couldn't find "Gensim" in the Python top 200 list: https://www.googleapis.com/download/storage/v1/b/ossf-criticality-score/o/python_top_200.csv?generation=1609361528959924&alt=media https://www.googleapis.com/download/storage/v1/b/ossf-critic... In the list of all projects, it is 2909th. https://www.googleapis.com/download/storage/v1/b/ossf-criticality-score/o/all.csv?generation=1612987910088811&alt=media https://www.googleapis.com/download/storage/v1/b/ossf-critic... You posted in December that it was #119 for Python. That suggests to me that this list might be quite volatile, which calls into question its usefulness. Regardless of the actual position in the list, your email should have got a response!
- giantandroids 6y ago> …where my request was left to rot, without any response. Hey, I am involved in the OpenSSF and happy to take at least a look. I maintain a popular python OSS project in the security area so we have that in common. Did your email actually go through, I just searched my list archives and there is nothing for gensim. EDIT: see your email now, have msg'ed the WG in slack. > Made me wonder whether this is just a PR stunt / corporate power grab I would not say it is, we have folks from OWASP on the technical advisory panel and many other non profit orgs / individual developers. One thing I would keep in mind, is that being a newly founded org, a lot of time has been spent working out and agreeing how we will operate, so the working groups are all still quite fresh.
- kimsterv 6y agoUnfortunately, the openssf members haven’t come to consensus on the process for handling funding requests and the process. We’ll get there (hopefully!) but it’s looking like it’s going to take more time. -Sincerely, Google’s OpenSSF governing board rep