ossf/tac
GitHub: ossf/tac
OpenSF 技术咨询委员会的治理仓库,负责管理基金会下属技术倡议的审批、生命周期与成熟度评估流程。
Stars: 148 | Forks: 83
# OpenSSF 技术咨询委员会 (TAC)
OpenSSF 技术咨询委员会负责监督 OpenSSF 的各项技术倡议 (TI)。
## 参与其中
虽然 TAC 由下列官方成员组成,但我们欢迎任何社区成员参与 TAC 的讨论。
官方交流在 [TAC 邮件列表](https://lists.openssf.org/g/openssf-tac/topics)上进行。[管理您对 Open SSF 邮件列表的订阅](https://lists.openssf.org/g/main/subgroups)。
非正式讨论在 [OpenSSF Slack](https://slack.openssf.org/)的 TAC 频道中进行。
要加入,请使用以下[邀请链接](https://join.slack.com/t/openssf/shared_invite/zt-xoktwsef-VzM~b22G2gfT_~4woTTsQA)。
使用 [GitHub Issues](https://github.com/ossf/tac/issues) 来请求和讨论议程项目。
如果您在此过程中的任何环节需要支持,请发送电子邮件至 [operations@openssf.org](mailto:operations@openssf.org?subject=GitHub%20Issue)。
## 会议
TAC 的[会议纪要](https://docs.google.com/document/d/1EieWyhKntZ7BzaZS97-BOybfMTUT4sZ72ViXq8QyYWs)已发布在网上,并出现在 [OpenSSF 社区日历](https://calendar.google.com/calendar?cid=czYzdm9lZmhwNWk5cGZsdGI1cTY3bmdwZXNAZ3JvdXAuY2FsZW5kYXIuZ29vZ2xlLmNvbQ)中。
会议也会被录制并发布到 [OpenSSF YouTube 频道](https://www.youtube.com/channel/UCUdhiXNEBEayowJXY_v7AXQ/)。
## TAC 成员
| 姓名 | 职位 | 电子邮件 | 组织 | 任期 |
| ---------------- | :--------: | ------------------------------ | ------------ | --------------------------|
| Arnaud J Le Hors | | lehors@us.ibm.com | IBM | 2026 年 1 月 - 2027 年 12 月 |
| Bob Callaway | 副主席 | bcallaway@google.com | Google | 2026 年 1 月 - 2026 年 12 月 |
| Michael Lieberman| | mike@kusari.dev | Kusari | 2025 年 1 月 - 2026 年 12 月 |
| Zach Steindler | 主席 | steiza@github.com | GitHub | 2026 年 1 月 - 2026 年 12 月 |
| Marcela Melara | | marcela.melara@intel.com | Intel | 2026 年 1 月 - 2027 年 12 月 |
| Michael Scovetta | | michael.scovetta@microsoft.com | Microsoft | 2026 年 1 月 - 2027 年 12 月|
| Stephen Augustus | | openssf@auggie.dev | Bloomberg L.P. | 2026 年 1 月 - 2026 年 12 月\* |
| Georg Kunz | | georg.kunz@ericsson.com | Ericsson | 2026 年 1 月 - 2026 年 12 月\* |
| Tracy Ragan| | tracy@deployhub.com | DeployHub | 2026 年 1 月 - 2026 年 12 月\* |
*注:标有 `*` 的条目表示由 OpenSSF 理事会任命的 TAC 成员;其他所有成员均由社区选举产生。*
## 章程
TAC 的章程是 [Open Source Security Foundation 章程](https://openssf.org/about/charter/)的一部分。
## 技术倡议
TI 的治理记录在[流程部分](process)中。本部分为您提供有关不同类型的倡议及其管理方式,以及如何提出新倡议的所有信息。它还涵盖了 TI 可以处于的不同成熟度级别、提升至下一级别必须满足的要求,以及每个级别所带来的权益。
以下技术倡议已获得 TAC 的批准。您可以通过它们的[季度报告](TI-reports)了解有关其状态的更多信息。
### 工作组 (WGs)
| 名称 | 代码库 | 备注 | 联系人 | 状态 |
| ------------------------------ | ------------------------------------ | ------------------ | ---------------- | ---------- |
| AI/ML 安全 | [GitHub](https://github.com/ossf/ai-ml-security) | [会议纪要](https://docs.google.com/document/d/1X7lCvAHY0x7HMaCQx-7KKPjSBPQ6v02TynQpOPXnXFI/edit) | Jeff Diecks | [孵化中](process/wg-lifecycle-documents/ai_ml_incubating_stage.md) |
| BEAR (归属感、赋能、同盟与代表性) | [GitHub](https://github.com/ossf/wg-bear) | [会议纪要](https://docs.google.com/document/d/17j8uN_radgNcY4G8u1Ua8FN__lUL4TeUN0gb-D2TrZ4/edit) | Stacey Potter | [孵化中](process/wg-lifecycle-documents/WG_DEI_incubating_stage.md) |
| 开源开发者最佳实践 | [GitHub](https://github.com/ossf/wg-best-practices-os-developers) | [会议纪要](https://docs.google.com/document/d/1u1gJMtOz-P5Z71B-vKKigzTbIDIS-bUNgNIcfnW4r-k/edit) | Jeff Diecks | [已毕业](process/wg-lifecycle-documents/BEST_practices_wg_graduation_stage.md) |
| 全球网络安全政策 | [GitHub](https://github.com/ossf/wg-globalcyberpolicy) | [会议纪要](https://docs.google.com/document/d/1iAplSQheMgemdMnEw74uPj3oi_6rLLbFFXhg4svqIDo/edit) | Jeff Diecks & Kris Borchers | [沙箱](process/wg-lifecycle-documents/Global_Cyber_Policy_WG_sandbox_stage.md) |
| ORBIT (基线、互操作性与工具开源资源) | [GitHub](https://github.com/ossf/wg-orbit) | [会议纪要](https://docs.google.com/document/d/1Hf-SsjYaAvY2Nk_jJ2-aHMqgBi1qg7oIj3PJWsCEe0U/edit?tab=t.0#heading=h.omyjy2x7t74i) | Jeff Diecks | [沙箱](process/wg-lifecycle-documents/ORBIT_WG_sandbox_stage.md) |
| 保护关键项目 | [GitHub](https://github.com/ossf/wg-securing-critical-projects) | [会议纪要](https://docs.google.com/document/d/1YkxOFs9x9YCtUfYeOG7Gy3OBX0cTDbZTEgOdvmEo6FE/edit) | Kris Borchers | [已归档](process/wg-lifecycle-documents/archive/securing_critical_projects_archived_stage.md) |
| 保护软件仓库 | [GitHub](https://github.com/ossf/wg-securing-software-repos) | [会议纪要](https://docs.google.com/document/d/18Y8HxntL2RkcgqoFdhdLpj17e4MOSCdskP1IoDiuP1s/edit) | Kris Borchers | [已毕业](process/wg-lifecycle-documents/securing_software_repositories_graduation_stage.md) |
| 安全工具 | [GitHub](https://github.com/ossf/wg-security-tooling) | [会议纪要](https://docs.google.com/document/d/190urQjwvE6DsjZ3Z1vBbNEXsJ--ccC8xHmbe_fYKRHA/edit) | Jeff Diecks | [已毕业](process/wg-lifecycle-documents/security_tooling_wg_graduation_stage.md) |
| 供应链完整性 | [GitHub](https://github.com/ossf/wg-supply-chain-integrity) | [会议纪要](https://docs.google.com/document/d/1moVFPn5pLi-uGs840_YBCrwdpHajU0ptFmlL4F9GryQ/edit) | Kris Borchers | 孵化中 |
| 漏洞披露 | [GitHub](https://github.com/ossf/wg-vulnerability-disclosures) | [会议纪要](https://docs.google.com/document/d/1TdxiFofLOfpHUEQILlKq7qkjSsRXVab0uApSDJ8c5rI/edit) | Jeff Diecks | [已毕业](process/wg-lifecycle-documents/Vuln_Disc_wg_graduation_stage.md) |
### 项目
| 名称 | 代码库 | 网站 | 赞助组织 | 状态 |
| ---------------------- | ---------------------------------------- | ----------------------------------------------------------------------------------------------------- | -------------- |---------- |
| 最佳实践徽章 | [GitHub](https://github.com/coreinfrastructure/best-practices-badge) | https://www.bestpractices.dev/ | 最佳实践 WG | 待定 |
| Bomctl | [GitHub](https://github.com/bomctl/bomctl) | | 安全工具 WG | [沙箱](process/project-lifecycle-documents/bomctl_sandbox_stage.md) |
| Criticality Score | [GitHub](https://github.com/ossf/criticality_score) | | 漏洞披露 WG | 待定 |
| darnit | [GitHub](https://github.com/kusari-oss/darnit) | | 供应链完整性 WG | [沙箱](process/project-lifecycle-documents/darnit_sandbox_stage.md) |
| Fuzz Introspector | [GitHub](https://github.com/ossf/fuzz-introspector) | | 安全工具 WG | 待定 |
| GUAC | [GitHub](https://github.com/guacsec/guac) | https://guac.sh | 供应链完整性 WG | [孵化中](process/project-lifecycle-documents/guac_incubating.md) |
| gittuf | [GitHub](https://github.com/gittuf/gittuf) | https://gittuf.dev/ | 供应链完整性 WG | [孵化中](process/project-lifecycle-documents/gittuf_incubating_stage.md) |
| OpenSSF Scorecard | [GitHub](https://github.com/ossf/scorecard) | https://securityscorecards.dev/ | 最佳实践 WG | [孵化中](process/project-lifecycle-documents/openssf_scorecard_incubating_stage.md) |
| OpenVEX | [GitHub](https://github.com/openvex) | | 漏洞披露 WG | [沙箱](process/project-lifecycle-documents/openvex_for_sandbox_stage.md) |
| OSV Schema | [GitHub](https://github.com/ossf/osv-schema) | https://ossf.github.io/osv-schema/ | 漏洞披露 WG | 待定 |
| 恶意软件包 | [GitHub](https://github.com/ossf/malicious-packages) | | 保护软件仓库 WG | [沙箱](process/project-lifecycle-documents/maliciouspackages_sandbox_stage.md) |
| Minder | [GitHub](https://github.com/mindersec/minder) | https://mindersec.dev/ | ORBIT WG | [沙箱](process/project-lifecycle-documents/minder_sandbox_stage.md) |
| 模型签名 | [GitHub](https://github.com/sigstore/model-transparency/blob/main/README.model_signing.md) | | AI/ML 安全 WG | [沙箱](process/project-lifecycle-documents/model_signing_sandbox_stage.md) |
| SAFE-Framework | [GitHub](https://github.com/SAFE-MCP/safe-mcp) | | AI/ML 安全 WG | [沙箱](process/project-lifecycle-documents/safe_framework_sandbox_stage.md) |
| 软件包分析 | [GitHub](https://github.com/ossf/package-analysis) | | 保护软件仓库 WG | 待定 |
| Protobom | [GitHub](https://github.com/protobom/protobom) | | 安全工具 WG | [沙箱](process/project-lifecycle-documents/protobom_sandbox_stage.md) |
| TUF 仓库服务 | [GitHub](https://github.com/repository-service-tuf/repository-service-tuf) | https://repository-service-tuf.readthedocs.io/ | 保护软件仓库 WG | [孵化中](process/project-lifecycle-documents/repository_service_for_tuf_incubation_stage.md) |
| S2C2F | [GitHub](https://github.com/ossf/s2c2f) | | 供应链完整性 WG | [孵化中](process/project-lifecycle-documents/s2c2f_incubation_stage.md) |
| SBOMit | [GitHub](https://github.com/sbomit) | | 安全工具 WG | [沙箱](process/project-lifecycle-documents/SBOMit_sandbox_stage.md) |
| 安全洞察规范 | [GitHub](https://github.com/ossf/security-insights-spec) | | ORBIT WG | 待定 |
| Sigstore | [GitHub](https://github.com/sigstore) | https://www.sigstore.dev/ | OpenSSF TAC | [已毕业](process/project-lifecycle-documents/sigstore_graduated_stage.md) |
| SLSA | [GitHub](https://github.com/slsa-framework/slsa) | https://slsa.dev/ | 供应链完整性 WG | [已毕业](process/project-lifecycle-documents/SLSA_graduation_stage.md) |
| Zarf | [GitHub](https://github.com/zarf-dev/zarf) | https://zarf.dev/ | 供应链完整性 WG | [沙箱](process/project-lifecycle-documents/zarf_sandbox_stage.md) |
### OpenSSF 附属项目
| 名称 | 代码库 | 状态 |
| -------------------------- | ----------------------------------- | ------ |
| Core Toolchain Infrastructure | https://git.coretoolchain.dev/ | 待定 |
| Alpha Omega | https://github.com/ossf/alpha-omega | 待定 |
### 特别兴趣小组
SIG 的创建和管理无需 TAC 的正式批准。以下内容仅供参考。
| 名称 | 代码库/主页 | 管理组织 |
| -------------------------- | -------------------- | ----------------------------- |
| CVD 指南 | https://github.com/ossf/oss-vulnerability-guide | 漏洞披露 WG |
| OpenVEX | https://github.com/ossf/OpenVEX | 漏洞披露 WG |
| 教育 | https://github.com/ossf/education | 最佳实践 WG |
| 内存安全 | https://github.com/ossf/Memory-Safety | 最佳实践 WG |
| C/C++ 编译器选项 | https://github.com/ossf/wg-best-practices-os-developers/tree/main/docs/Compiler-Hardening-Guides | 最佳实践 WG |
| Python 加固 | https://github.com/ossf/wg-best-practices-os-developers/tree/main/docs/Secure-Coding-Guide-for-Python | 最佳实践 WG |
| 安全基线 | https://github.com/ossf/security-baseline | ORBIT WG |
| SBOM Everywhere | https://github.com/ossf/sbom-everywhere | 安全工具 WG |
| OSS 模糊测试 | https://github.com/ossf/wg-security-tooling?tab=readme-ov-file#oss-fuzzing-sig | 安全工具 WG |
### 概览图
包含 OpenSSF(包括其项目和 SIG)概览的图表可在 [OpenSSF 介绍(包括图表绘制者协会图表)](https://docs.google.com/presentation/d/1DpB-WPz4yimdF7DDH4waR_zdi7X5WumgoptcqwkMg-s/edit?usp=sharing)演示文稿中找到,该演示文稿由 [OpenSSF 图表绘制者协会](https://github.com/ossf/Diagrammers-Society)创建和维护。
## 反垄断政策
Linux Foundation 的会议涉及行业内竞争对手的参与,Linux Foundation 旨在根据适用的反垄断和竞争法开展其所有活动。因此,与会者严格遵守会议议程至关重要,并且必须了解并避免参与适用美国州、联邦或外国反垄断法和竞争法所禁止的任何活动。
《Linux Foundation 反垄断政策》中描述了在 Linux Foundation 会议及与 Linux Foundation 活动相关场合被禁止的行为类型示例,该政策可在 获取。如果您对这些问题有疑问,请联系您公司的法律顾问;如果您是 Linux Foundation 的成员,请随时联系 Gesmer Updegrove LLP 律师事务所的 Andrew Updegrove,该律师事务所为 Linux Foundation 提供法律顾问服务。
标签:Linux 内核安全, 开源安全基金会, 开源治理, 技术委员会, 社区管理, 防御加固, 项目管理