Skip to content

SDLC Framework WG Bi-weekly call - August 3rd 2026 #305

Description

@aaronsearle

Date

20th June 2026 - 10am EST / 3pm UK

Untracked attendees

Name Firm Comment

Meeting notices

  • FINOS Project leads are responsible for observing the FINOS guidelines for running project meetings. Project maintainers can find additional resources in the FINOS Maintainers Cheatsheet.

  • All participants in FINOS project meetings are subject to the LF Antitrust Policy, the FINOS Community Code of Conduct and all other FINOS policies.

  • FINOS meetings involve participation by industry competitors, and it is the intention of FINOS and the Linux Foundation to conduct all of its activities in accordance with applicable antitrust and competition laws. It is therefore extremely important that attendees adhere to meeting agendas, and be aware of, and not participate in, any activities that are prohibited under applicable US state, federal or foreign antitrust and competition laws. Please contact legal@finos.org with any questions.

  • FINOS project meetings may be recorded for use solely by the FINOS team for administration purposes. In very limited instances, and with explicit approval, recordings may be made more widely available.

Agenda

  • Convene, roll call, welcome new people
  • Approve previous meeting minutes
  • CFP submitted with
  • Site logo finos-labs/SDLC-Controls-Framework#6
  • Control review - Content Addressable naes
  • Control review - Software Binary Provenance
  • AOB, Q&A & Adjourn (5mins)

Notes

  • Discussed the new long/short meeting schedule having been formalised
  • Discussed the progress on moving out of labs and the lack of a public announcement
  • CFP being submitted for a shared talk, not waiting for the workshop CFP, we will submit anyway.
  • Discussed additional reviews from a risk perspective
  • Review of Content Addressable Identities
    • Potentially for a "meta" control
    • Very hard to audit since it requires finding all use of the identities
    • Building block for other controls
    • Need to reference within other controls
    • Should be changed to call out that the names should be immutable or content addressable
  • Review of Software Artifact Provenance
    • add version control mitigation
    • add content addressable
    • Should be changed to call out that the names should be immutable or content addressable
    • We need trusted source or verifiable source as a requirement, e.g an approved signer.
    • Use a dedicated provenance store or attestation service to maintain build records independently of the CI/CD system <- revise this to not be specific about ci/cd could be anywhere

Follow Ups

  • Create an ordered list of controls for us to review.
  • Add new tag for meta controls, describe what we require of them.

Zoom info

Join Zoom Meeting

Github Repo: https://github.com/finos/devops-automation/

Project Board: https://github.com/orgs/finos/projects/33

Mailing List: Email devops-mutualization+subscribe@finos.org to subscribe to our mailing list

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions