-
Notifications
You must be signed in to change notification settings - Fork 42
Description
@zmanion has presented to the working group several times now about VINCE (now called "Advise"). Advise(1) is an open source tool that provides a platform to manage coordinated vulnerability disclosures.
It is proposed that the OpenSSF accept the donation of Advise as a Sandbox project within the Vulnerability Disclosures Working Group, work with the existing project members to make Advise an option for open source projects to manage and coordinate their intake of security vulnerabilities, and assist the project team in enhancements and evangelism of the project within the upstream open source community. This directly falls in line with previous plans the group discussed(2) around the creation of an opens source SIRT, as a key capability security teams should have.
This proposal does NOT have anything to do with existing implementations of VINCe/Advise and the services currently being provided. It is purely about the donate of the code to the Foundation for curation, enhancement, and evangelism alongside out other CVD & Vuln metadata efforts.
If the WG agrees with this path forward, we would work with the project to complete the necessary paperwork(3) for the foundation to adopt Advise as a Sandbox project within this working group.
(1) - https://github.com/vu-ls/advise
(2) - https://github.com/ossf/SIRT/blob/main/plan/2.0%20Identify%20Core%20Services%20and%20Processes.md
(3) - https://github.com/ossf/tac/blob/main/process/project-lifecycle.md