Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Governance Review]: in-toto #733

Closed
trishankatdatadog opened this issue Oct 16, 2024 · 2 comments · Fixed by #740
Closed

[Governance Review]: in-toto #733

trishankatdatadog opened this issue Oct 16, 2024 · 2 comments · Fixed by #740

Comments

@trishankatdatadog
Copy link
Contributor

trishankatdatadog commented Oct 16, 2024

Project Name

in-toto

Project Website

https://in-toto.io/

Contact Details 1

@SantiagoTorres

Contact Details 2

@JustinCappos

Links to communication channels

https://cloud-native.slack.com/archives/C056XS0VD6K

Reason for governance review request

Application for moving levels from Incubation to Graduation

Are there any sub-projects, plugins, and related?

  • Most reference implementations of in-toto are listed here
  • Witness and Archivista are two projects that have been donated by TestifySec to the in-toto org
  • Major integrations or deployments of in-toto are listed here
  • The Attestation framework is a notable subproject used heavily by SLSA (an OpenSSF project)
  • SBOMit, GUAC, and gittuf are other OpenSSF projects that also use in-toto
  • Last but not least, Sigstore is another major OpenSSF project that also heavily uses in-toto

Governance model

We took the governance model from graduated projects like SPIFFE and lightly adapted it to meet our needs. We have a spec-based project (as does SPIFFE), which has a variety of different implementations that are managed by diverse groups. So, we felt this made the most sense.

Governance documents

Governance Execution Examples

Governance Evolution

We switched from a “BDFL” model to the more horizontal model we use today in January of 2023: in-toto/community#3

Any specific aspects of your governance structure are you seeking feedback on?

No response

Do you have any concerns or specific areas where you feel your governance could be improved?

No response

Additional notes and resources

We look forward to your review, so please let us know if you have questions. Thanks!

@jberkus
Copy link
Contributor

jberkus commented Oct 18, 2024

@trishankatdatadog thanks! Some questions/follow-up:

Are there any sub-projects, plugins, and related?

This section is for sub-projects of In-Toto. Not for integrations, users, etc. We're looking for subprojects/WGs/SIGs/teams/whatever that form semi-autonmous groups within the project -- if you have any. A lot of projects do not. Please update, thanks.

We switched from a “BDFL” model to the more horizontal model we use today in January of 2023: in-toto/community#3

Any commentary on how that transition went? Anything you particularly would like us to look at?

Like a security audit, the governance review is your chance to have an independant 3rd party examine your "project paperwork" and make suggestions. So please add anything you'd like us to review for your benefit.

@trishankatdatadog
Copy link
Contributor Author

@trishankatdatadog thanks! Some questions/follow-up:

Are there any sub-projects, plugins, and related?

This section is for sub-projects of In-Toto. Not for integrations, users, etc. We're looking for subprojects/WGs/SIGs/teams/whatever that form semi-autonmous groups within the project -- if you have any. A lot of projects do not. Please update, thanks.

We switched from a “BDFL” model to the more horizontal model we use today in January of 2023: in-toto/community#3

Any commentary on how that transition went? Anything you particularly would like us to look at?

Like a security audit, the governance review is your chance to have an independant 3rd party examine your "project paperwork" and make suggestions. So please add anything you'd like us to review for your benefit.

Thanks, Josh. I'm busy traveling in an opposite time zone at the moment, but I'll confer with the rest of the in-toto Steering Committee, and will keep you posted.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Development

Successfully merging a pull request may close this issue.

4 participants