Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

In-toto Graduation DD - TOC evaluation #1522

Open
wants to merge 50 commits into
base: main
Choose a base branch
from
Open

In-toto Graduation DD - TOC evaluation #1522

wants to merge 50 commits into from

Conversation

linsun
Copy link
Contributor

@linsun linsun commented Jan 15, 2025

This PR contains the due diligence for in-toto to move to graduation status.

Project application issue: #1162

The in-toto project has completed the criteria that show its maturity at the applied graduation level. The adopter interviews reflect the in-toto project is in use for the graduation level with happy adopters.

This PR is now available for TOC review and public comment.

Copy link
Contributor

@TheFoxAtWork TheFoxAtWork left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Providing review and approval for when the vote is opened.

@TheFoxAtWork
Copy link
Contributor

Linking to the mailing list notification for public comment on this project: https://lists.cncf.io/g/cncf-toc/message/8742

raravena80 and others added 27 commits January 21, 2025 11:11
Signed-off-by: Ricardo Aravena <[email protected]>

Signed-off-by: Ricardo Aravena <[email protected]>
Signed-off-by: Lin Sun <[email protected]>
Signed-off-by: Lin Sun <[email protected]>
Signed-off-by: Lin Sun <[email protected]>
Why:
 * it was requested the TOC describe used competencies for their work to better inform candidates
 * it was requested the TOC explicitly state minimum throughput for Due Diligence

This change address the need by:
 * Adding explicit throughput on line 39 for accountability
 * Establish initial competencies at line 47

Signed-off-by: Emily Fox <[email protected]>
Signed-off-by: Lin Sun <[email protected]>
Signed-off-by: Emily Fox <[email protected]>
Signed-off-by: Lin Sun <[email protected]>
Signed-off-by: Emily Fox <[email protected]>
Signed-off-by: Lin Sun <[email protected]>
Signed-off-by: Emily Fox <[email protected]>
Signed-off-by: Lin Sun <[email protected]>
Signed-off-by: Kevin Wang <[email protected]>
Signed-off-by: Lin Sun <[email protected]>
Signed-off-by: Kevin Wang <[email protected]>
Signed-off-by: Lin Sun <[email protected]>
Signed-off-by: Kevin Wang <[email protected]>
Signed-off-by: Lin Sun <[email protected]>
Co-authored-by: Emily Fox <[email protected]>
Signed-off-by: Kevin Wang <[email protected]>
Signed-off-by: Lin Sun <[email protected]>
Signed-off-by: Kevin Wang <[email protected]>
Signed-off-by: Lin Sun <[email protected]>
Why:
 * the TOC has fielded feedback from maintainers and TOC members, implemented changes to address issues, and needs to update our docs to reflect this.

This change address the need by:
 * re-writing the triage to align with current process
 * calling out the adopter form for adopter interview collection
 * detail process for projects not yet ready to move
 * linking the adopter interview form in the process/README
 * updating process/README to inform on triaging and not-ready applications

Signed-off-by: Emily Fox <[email protected]>
Signed-off-by: Lin Sun <[email protected]>
Signed-off-by: Emily Fox <[email protected]>
Signed-off-by: Lin Sun <[email protected]>
Signed-off-by: lianmakesthings <[email protected]>
Signed-off-by: Lin Sun <[email protected]>
Signed-off-by: leonrayang <[email protected]>
Signed-off-by: Lin Sun <[email protected]>
Signed-off-by: Bob Killen <[email protected]>
Signed-off-by: Lin Sun <[email protected]>
Signed-off-by: Emily Fox <[email protected]>
Signed-off-by: Lin Sun <[email protected]>
WIP update to emily's comment

Signed-off-by: Lin Sun <[email protected]>
more updates

Signed-off-by: Lin Sun <[email protected]>
more updates

Signed-off-by: Lin Sun <[email protected]>
linsun and others added 22 commits January 21, 2025 11:11
Signed-off-by: Ricardo Rocha <[email protected]>
Signed-off-by: Lin Sun <[email protected]>
Add a link to the template to ensure user review the moving level evaluation guideline

Signed-off-by: Lin Sun <[email protected]>
adding more info related to audit and maintainers

Signed-off-by: Lin Sun <[email protected]>
address more comments on active maintainers and security audit.

Signed-off-by: Lin Sun <[email protected]>
Signed-off-by: Davanum Srinivas <[email protected]>
Signed-off-by: Lin Sun <[email protected]>
As per the discussion in the TOC meeting of 2025-01-07
(https://youtu.be/dTzpAw6lUT0?t=1627), add a set of
questions to the adopter interview template that will allow us to get a
better picture of how adopters see and use these maturity levels.

Signed-off-by: Ricardo Rocha <[email protected]>
Signed-off-by: Lin Sun <[email protected]>
@linsun
Copy link
Contributor Author

linsun commented Jan 21, 2025

No code change, just correcting DCO using these 2 cmds:

git rebase HEAD~30 --signoff
git push --force-with-lease origin main

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: TOC Review & Public Comment
Development

Successfully merging this pull request may close these issues.

9 participants