Skip to content

Draft: Adopt FINOS Community Specification License and standards governance boilerplate - #101

Draft
TheJuanAndOnly99 wants to merge 4 commits into
mainfrom
cleanup-finos-standards-boilerplate
Draft

TheJuanAndOnly99 wants to merge 4 commits into
mainfrom
cleanup-finos-standards-boilerplate

Conversation

@TheJuanAndOnly99

@TheJuanAndOnly99 TheJuanAndOnly99 commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

DO NOT MERGE. LF Legal to review first.

Summary

Draft PR for legal review. Instantiates the FINOS Standards Project blueprint’s GitHub-conventional layout for the SDLC Common Controls Catalog (Community Specification License 1.0 for specifications; Apache-2.0 for source).

Licensing (primary review focus)

  • Replace root LICENSE.md with short dual-license LICENSE
  • Add LICENSES/SPECIFICATION-LICENSE (CSL 1.0) and LICENSES/SOURCE-CODE-LICENSE (Apache-2.0)
  • Keep LICENSE.spdx as Community-Spec-1.0 AND Apache-2.0

Governance layout

  • Move working files to root: GOVERNANCE.md, CONTRIBUTING.md, CODE_OF_CONDUCT.md, SCOPE.md, NOTICES.md, PARTICIPANTS.md
  • Keep only CLA + draft template in governance-documents/ (CS_Contributor_License_Agreement.md, CS_Template.md)
  • Remove numbered 0._8._ Community Specification document set from this repo

Project wiring

  • Update enrollment PR template and CLA links for this project
  • Update README / site footer away from CC-BY-4.0 project licensing

@github-actions

github-actions Bot commented Aug 24, 2026

Copy link
Copy Markdown

Readiness Check

SDLC Controls Framework — Readiness Report

Generated: 2026-08-25

Scope: changed files only

Risks

ID Title Doc Status Type Sections Cross-refs Ready

Mitigations

ID Title Doc Status Type Sections Mitigates Reg. Refs Cross-refs Ready
mi-1 Code Review Draft PREV

Framework Validation Coverage

Reference IDs are validated against a data file when one is available.

Framework Status
eu-ai-act ✅ validated (checksum ok)
ffiec-itbooklets ✅ validated (checksum ok)
iso-42001 ✅ validated (checksum ok)
iso-iec-27002 ⚠️ content changed since the checksum was recorded — run scripts/readiness-check --update-checksums if this was intentional
nist-ai-600-1 ✅ validated (checksum ok)
nist-sp-800-53r5 ✅ validated (checksum ok)
nist-ssdf ✅ validated (checksum ok)
owasp-llm ✅ validated (checksum ok)
owasp-ml ✅ validated (checksum ok)
slsa ✅ validated (checksum ok)

Risk–Mitigation Coverage Matrix

Risk mi-1

Move CSL governance files to root conventions, split full license
texts under LICENSES/, and update enrollment/templates for legal review.

Signed-off-by: Juan Estrella <juan.estrella@finos.org>
Signed-off-by: Juan Estrella <juan.estrella@finos.org>
Signed-off-by: Juan Estrella <juan.estrella@finos.org>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant