2017-10-24 Meeting notes

Table of Contents

Date

Agenda

TimeItemWhoNotes
5 minConvene & roll call

10 minReview action items from previous meetings

See above

10 minDiscussion: Linux Foundation open source request templateAaron Williamson
15 minDiscussion: draft policy outlineAaron Williamson
15 minDiscussion: surveillance of Github & other collaboration toolsAaron WilliamsonFormer user (Deleted)
5 minAOB & adjourn

Attendees

NameOrganisationPresent / Absent
Symphony Software FoundationY
Gabriele CataniaBlackRockY
Former user (Deleted)Scott Logic
Doug FriedmanTradeweb
Justin PetersonTradewebY
Lawrence Miller (Deactivated)Symphony LLC
Rhyddian OldsDeutsche Bank
Former user (Deleted)IHS MarkitY
Former user (Deleted)Credit Suisse
Ken Watson (Deactivated)Ipreo
Peter MonksSymphony Software Foundation

Actions items from previous meetings

Task report

Looking good, no incomplete tasks.

Add new action items here.

Meeting notes

The members reviewed the Linux Foundation's template open source request form and discussed which items were relevant to their processes.

A common process discussed is that open source components are reviewed once upon importation to internal repositories (e.g. Artifactory). Requests are made via a ticketing system like Jira. Developers aren't required to provide much information in their requests. The open source review board become the de facto owners of the open source components after approval, so it's incombent on them to do appropriate dilligence. The information stored about each component includes: owner, whether approval is for production or non-production (i.e. distributed or hosted) use, and any vulnerability information. There is then a less rigorous approval process for version updates. OSRB tracks where packages are deployed geographically because that impacts regulatory concerns. There was agreement that it would be useful to collect information on which clients are affected by each components, for security notification purposes.


Need help? Email help@finos.org we'll get back to you.

Content on this page is licensed under the CC BY 4.0 license.
Code on this page is licensed under the Apache 2.0 license.