The OpenChain Specification Work Group held its regular monthly call on the 7th of May. You can review the full recording below.
We were working on the draft next generation security assurance specification:
https://github.com/OpenChain-Project/Security-Assurance-Specification/blob/main/Security-Assurance-Specification/2.0/en/openchain-security-specification-2.0.md
and
The draft next generation licensing compliance specification:
https://github.com/OpenChain-Project/License-Compliance-Specification/blob/master/3.0/en/openchain-license-compliance-3.0.md
For security we were coming to a conclusion on this issue:
[Improvement] Expand definitions section for (1) Secure Software Development to include Secure Programming Techniques and (2) Security Testing to include Static and Dynamic #36https://github.com/OpenChain-Project/Security-Assurance-Specification/issues/36
And for licensing we were coming to a conclusion on this issue:
Verification Material For Training – next iteration #38
https://github.com/OpenChain-Project/License-Compliance-Specification/issues/38
Both issue are read to close pending any objections, and therefore there is a two-week period – before the forthcoming North America / Asia call – to review and add any notes.
We also opened one new issue for review in future calls:
[Improvement] Review Cycle Potentially Needs Adjustment #71https://github.com/OpenChain-Project/License-Compliance-Specification/issues/71
Join Our Work
Everyone is welcome to be part of the Specification Work Group. You can join their mailing list here:
https://lists.openchainproject.org/g/specification/