Vote result: 10 yes, 0 no, for "Should OpenSSF release “Fundamentals of Developing Secure S/W”?"


David A. Wheeler
 

This week we had a vote on Doodle for the question:
Should OpenSSF release “Fundamentals of Developing Secure S/W”?
The voting period has ended.

The vote was 10 yes and 0 no, so it passed overwhelmingly.
Details here: https://doodle.com/poll/wkwgpzmbhmmgdy3f

Thank you very much everyone!

I will instruct the LF Education folks to find a way to make it clear
that this is an OpenSSF product. I don't know exactly what that
involves, but the key first step is deciding whether or not to do
that, and that question has been answered. The current expectation is
that the Oct 30 OpenSSF press release will include information that
the course exists & signups can begin; the course itself is expected
to open on EdX in early November.

My current understanding is that the TAC and GB don't need to do
anything. However, if that's incorrect, or plans have changed, I'd be
happy to assist if needed. I wasn't sure if I should send this
information to the TAC or GB mailing lists, so I haven't done that.
Anyone is free to repost to the other mailing lists if you think it
should be!! I imagine that this vote should be mentioned at the 9/22
TAC meeting.

--- David A. Wheeler
Director of Open Source Supply Chain Security, The Linux Foundation


Kay Williams <kayw@...>
 

Adding openssf-gb-strategy-committee@ for visibility.

Great news, thanks everyone for moving this forward. It will make a great addition to our 10/30 press release. :-)

David and @openssf-wg-best-practices@... - can you also complete the following?

Propose a communications plan for announcing the course:
* website (openssf.org) - how do we want to expose educational materials generally, and this course specifically, on the OpenSSF website (openssf.org) (Lindsay can help us review and implement with the website designers)
* press release - draft a paragraph for how we want to describe the course in our press release (Lindsay can help us work with the PR firm to wordsmith and finalize)
* blog - do we want to have a blog article specific to the course? (Lindsay is working on setting up blog capability for the website, more details later)
* anything else?

Would it be possible to a proposal with the gb-strategy-committee at the 9/28 meeting?

I created an issue in the gb-strategy-committee repo for tracking and discussion - https://github.com/ossf/gb-strategy-committee/issues/16

(Note - thanks @Lindsay Gendreau for all your help!)

Thanks everyone!
Kay

-----Original Message-----
From: David A. Wheeler <dwheeler@...>
Sent: Friday, September 18, 2020 8:50 AM
To: openssf-wg-best-practices@...
Cc: Kay Williams <kayw@...>; Ryan Haning <ryhaning@...>; Dan Lorenc <dlorenc@...>; Michael Dolan <mdolan@...>; Chris Aniszczyk <caniszczyk@...>; Kim Lewandowski <klewandowski@...>
Subject: Vote result: 10 yes, 0 no, for "Should OpenSSF release “Fundamentals of Developing Secure S/W”?"

This week we had a vote on Doodle for the question:
Should OpenSSF release “Fundamentals of Developing Secure S/W”?
The voting period has ended.

The vote was 10 yes and 0 no, so it passed overwhelmingly.
Details here: https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdoodle.com%2Fpoll%2Fwkwgpzmbhmmgdy3f&;data=02%7C01%7Ckayw%40microsoft.com%7C32cb6f3acfdb451ae35408d85be22b10%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637360374230062114&amp;sdata=dk2pc%2FOoNsg0I32GD8OCI%2BWMc%2BI3AzaiUpEaeCqowQo%3D&amp;reserved=0

Thank you very much everyone!

I will instruct the LF Education folks to find a way to make it clear that this is an OpenSSF product. I don't know exactly what that involves, but the key first step is deciding whether or not to do that, and that question has been answered. The current expectation is that the Oct 30 OpenSSF press release will include information that the course exists & signups can begin; the course itself is expected to open on EdX in early November.

My current understanding is that the TAC and GB don't need to do anything. However, if that's incorrect, or plans have changed, I'd be happy to assist if needed. I wasn't sure if I should send this information to the TAC or GB mailing lists, so I haven't done that.
Anyone is free to repost to the other mailing lists if you think it should be!! I imagine that this vote should be mentioned at the 9/22 TAC meeting.

--- David A. Wheeler
Director of Open Source Supply Chain Security, The Linux Foundation