diff --git a/TI-reports/2025/2025-Q1-Repos-WG.md b/TI-reports/2025/2025-Q1-Repos-WG.md new file mode 100644 index 00000000..655a8069 --- /dev/null +++ b/TI-reports/2025/2025-Q1-Repos-WG.md @@ -0,0 +1,52 @@ +# 2025 Q1 Securing Software Repositories Working Group + +## Overview + +**Mission**: Improve security of software repositories (npm, PyPI, RubyGems, ...) by providing a forum for discussion, a maturity model for security roadmaps, and guidance for individual security capabilities. + +**Links**: +- [GitHub repository](https://github.com/ossf/wg-securing-software-repos) +- [Slack channel](https://openssf.slack.com/archives/C034CBLMQ9G) +- [WG meeting docs](https://docs.google.com/document/d/18Y8HxntL2RkcgqoFdhdLpj17e4MOSCdskP1IoDiuP1s/edit?usp=sharing) + +## Securing Software Repositories Working Group + +### Purpose + +Improve security of software repositories by providing a forum for discussion, a maturity model for security roadmaps, and guidance for individual security capabilities. + +### Current Status + +- [Central now performs Sigstore Signature Validation](https://central.sonatype.org/news/20250128_sigstore_signature_validation_via_portal/) +- [Posting for technical writer](https://jobs.smartrecruiters.com/LinuxFoundation/744000038830864-openssf-securing-repositories-working-group-technical-writer) to write package yanking guidance is live +- Letter of support to Python Software Foundation's grant request to US National Science Foundation on detecting, flagging, and quarantining malware +- Meetings continue every other week, with async discussions in the Slack channel + +### Up Next + +- Hire contractor; publish package yanking guidance +- [Funding request: UI/UX support for attestations on software repos](https://github.com/ossf/tac/issues/424) +- Continue supporting landing security capabilities in software repositories + +### Questions/Issues for the TAC + +- None at this time + +## RSTUF Project + +### Purpose + +Provide a service to protect repository index from tampering by distributing them with The Update Framework (TUF) + +### Current Status + +- Continuing to work towards v1.0 release to run alongside RubyGems and PyPI and sign their repository index +- [Funding approved: 2025 cloud development costs](https://github.com/ossf/tac/issues/417) + +### Up Next + +- [Security audit with OSTIF](https://github.com/ossf/tac/issues/379) + +### Questions/Issues for the TAC + +- None at this time