Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Provide a machine-readable version of the list under source control #45

Open
bureado opened this issue Jan 11, 2022 · 0 comments
Open

Comments

@bureado
Copy link

bureado commented Jan 11, 2022

The list of critical open source projects, components and framework is currently published as a spreadsheet.

I suggest that it's provided as a machine-readable file under source control in this repository. This can provide a mostly durable endpoint for people that need to access it for other purposes. It can also help with clarity and readability (the spreadsheet seems to mention other projects that didn't meet the initial criteria) and it can help formalize the governance process at least for releases (see #23) At the very least it can serve to decouple the eligibility/evaluation criteria from the actual list of software components.

It'd be great to consider publishing this list in, e.g., SPDX format. A key question is how to normalize the project names. I mention using the repology rules in #41. purl is another potential addition to the list. And, as mentioned in other issues, WikiData can be surprisingly helpful going from a "named package" to the specifics of what it is exactly (see this example for nano)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant