From fc3cd193296e44210d2b47e2d2975baab75bcd33 Mon Sep 17 00:00:00 2001 From: Justin Murphy <96064251+justmurphy@users.noreply.github.com> Date: Tue, 17 Dec 2024 09:31:28 -0500 Subject: [PATCH 01/19] add directory structure for meeting minutes --- meeting-minutes/{ => 2023}/2023-11-02.md | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename meeting-minutes/{ => 2023}/2023-11-02.md (100%) diff --git a/meeting-minutes/2023-11-02.md b/meeting-minutes/2023/2023-11-02.md similarity index 100% rename from meeting-minutes/2023-11-02.md rename to meeting-minutes/2023/2023-11-02.md From ab379fc55987f38040a1d9b07003e72ecbad6a3f Mon Sep 17 00:00:00 2001 From: Justin Murphy <96064251+justmurphy@users.noreply.github.com> Date: Tue, 17 Dec 2024 09:32:22 -0500 Subject: [PATCH 02/19] add 2024 directory --- meeting-minutes/{ => 2024}/2024-01-24.md | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename meeting-minutes/{ => 2024}/2024-01-24.md (100%) diff --git a/meeting-minutes/2024-01-24.md b/meeting-minutes/2024/2024-01-24.md similarity index 100% rename from meeting-minutes/2024-01-24.md rename to meeting-minutes/2024/2024-01-24.md From e4634eb07aac425bf8ef3497bd83abde3c83c940 Mon Sep 17 00:00:00 2001 From: Justin Murphy <96064251+justmurphy@users.noreply.github.com> Date: Tue, 17 Dec 2024 09:33:32 -0500 Subject: [PATCH 03/19] move Feb minutes --- meeting-minutes/{ => 2024}/2024-02-21.md | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename meeting-minutes/{ => 2024}/2024-02-21.md (100%) diff --git a/meeting-minutes/2024-02-21.md b/meeting-minutes/2024/2024-02-21.md similarity index 100% rename from meeting-minutes/2024-02-21.md rename to meeting-minutes/2024/2024-02-21.md From 76e29c18fdc10710f6b05ba114f99b5c0b078444 Mon Sep 17 00:00:00 2001 From: Justin Murphy <96064251+justmurphy@users.noreply.github.com> Date: Tue, 17 Dec 2024 09:34:47 -0500 Subject: [PATCH 04/19] add march minutes --- meeting-minutes/{ => 2024}/2024-03-20.md | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename meeting-minutes/{ => 2024}/2024-03-20.md (100%) diff --git a/meeting-minutes/2024-03-20.md b/meeting-minutes/2024/2024-03-20.md similarity index 100% rename from meeting-minutes/2024-03-20.md rename to meeting-minutes/2024/2024-03-20.md From 43292444e014be4c7f8e270bccd9880a4f9d0064 Mon Sep 17 00:00:00 2001 From: Justin Murphy <96064251+justmurphy@users.noreply.github.com> Date: Tue, 17 Dec 2024 09:37:26 -0500 Subject: [PATCH 05/19] add april minutes to 2024 --- meeting-minutes/{ => 2024}/2024-04-17.md | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename meeting-minutes/{ => 2024}/2024-04-17.md (100%) diff --git a/meeting-minutes/2024-04-17.md b/meeting-minutes/2024/2024-04-17.md similarity index 100% rename from meeting-minutes/2024-04-17.md rename to meeting-minutes/2024/2024-04-17.md From ffe81903780ec48449ba3d5e2f1aa4dc11b160f1 Mon Sep 17 00:00:00 2001 From: Justin Murphy <96064251+justmurphy@users.noreply.github.com> Date: Tue, 17 Dec 2024 09:38:50 -0500 Subject: [PATCH 06/19] add may minutes to 2024 --- meeting-minutes/{ => 2024}/2024-05-15.md | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename meeting-minutes/{ => 2024}/2024-05-15.md (100%) diff --git a/meeting-minutes/2024-05-15.md b/meeting-minutes/2024/2024-05-15.md similarity index 100% rename from meeting-minutes/2024-05-15.md rename to meeting-minutes/2024/2024-05-15.md From 7195fda26b72e26f5d816876a08da34fbd0ef9fb Mon Sep 17 00:00:00 2001 From: Justin Murphy <96064251+justmurphy@users.noreply.github.com> Date: Tue, 17 Dec 2024 09:40:32 -0500 Subject: [PATCH 07/19] add june minutes to 2024 --- meeting-minutes/{ => 2024}/2024-06-19.md | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename meeting-minutes/{ => 2024}/2024-06-19.md (100%) diff --git a/meeting-minutes/2024-06-19.md b/meeting-minutes/2024/2024-06-19.md similarity index 100% rename from meeting-minutes/2024-06-19.md rename to meeting-minutes/2024/2024-06-19.md From cf14274a71d9ac3aebfa3d4bcd4e73cb5f730228 Mon Sep 17 00:00:00 2001 From: Justin Murphy <96064251+justmurphy@users.noreply.github.com> Date: Tue, 17 Dec 2024 09:41:36 -0500 Subject: [PATCH 08/19] add july minutes to 2024 --- meeting-minutes/{ => 2024}/2024-07-17.md | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename meeting-minutes/{ => 2024}/2024-07-17.md (100%) diff --git a/meeting-minutes/2024-07-17.md b/meeting-minutes/2024/2024-07-17.md similarity index 100% rename from meeting-minutes/2024-07-17.md rename to meeting-minutes/2024/2024-07-17.md From 38b4d8cd6534dcce0de06c5fc218edd47c6f1644 Mon Sep 17 00:00:00 2001 From: Justin Murphy <96064251+justmurphy@users.noreply.github.com> Date: Tue, 17 Dec 2024 09:45:52 -0500 Subject: [PATCH 09/19] Create 2024-08-21.md --- meeting-minutes/2024/2024-08-21.md | 5 +++++ 1 file changed, 5 insertions(+) create mode 100644 meeting-minutes/2024/2024-08-21.md diff --git a/meeting-minutes/2024/2024-08-21.md b/meeting-minutes/2024/2024-08-21.md new file mode 100644 index 0000000..4b8731b --- /dev/null +++ b/meeting-minutes/2024/2024-08-21.md @@ -0,0 +1,5 @@ +# 1. Opening Activities + +## 1.1 Opening comments (Co-Chair) + +## 1.2 Introduction of participants/roll call (Co-Chair) From 6d13bcdb2ff5efdc9915e70c9f193e334e36e403 Mon Sep 17 00:00:00 2001 From: Justin Murphy <96064251+justmurphy@users.noreply.github.com> Date: Tue, 17 Dec 2024 09:47:54 -0500 Subject: [PATCH 10/19] add october meeting minutes to 2024 --- meeting-minutes/{ => 2024}/2024-10-16.md | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename meeting-minutes/{ => 2024}/2024-10-16.md (100%) diff --git a/meeting-minutes/2024-10-16.md b/meeting-minutes/2024/2024-10-16.md similarity index 100% rename from meeting-minutes/2024-10-16.md rename to meeting-minutes/2024/2024-10-16.md From 1d9d69665aa9bc3ca2e3788f3d04bfd247e05dfc Mon Sep 17 00:00:00 2001 From: Justin Murphy <96064251+justmurphy@users.noreply.github.com> Date: Tue, 17 Dec 2024 09:49:29 -0500 Subject: [PATCH 11/19] add november meeting minutes to 2024 --- meeting-minutes/{ => 2024}/2024-11-20.md | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename meeting-minutes/{ => 2024}/2024-11-20.md (100%) diff --git a/meeting-minutes/2024-11-20.md b/meeting-minutes/2024/2024-11-20.md similarity index 100% rename from meeting-minutes/2024-11-20.md rename to meeting-minutes/2024/2024-11-20.md From 49ede5c9cfd8a46439b8f42e44ca7600b9bf3fb5 Mon Sep 17 00:00:00 2001 From: Justin Murphy <96064251+justmurphy@users.noreply.github.com> Date: Tue, 17 Dec 2024 09:55:46 -0500 Subject: [PATCH 12/19] add meeting outline structure --- meeting-minutes/2024/2024-08-21.md | 44 ++++++++++++++++++++++++++++++ 1 file changed, 44 insertions(+) diff --git a/meeting-minutes/2024/2024-08-21.md b/meeting-minutes/2024/2024-08-21.md index 4b8731b..508b969 100644 --- a/meeting-minutes/2024/2024-08-21.md +++ b/meeting-minutes/2024/2024-08-21.md @@ -3,3 +3,47 @@ ## 1.1 Opening comments (Co-Chair) ## 1.2 Introduction of participants/roll call (Co-Chair) + +## 1.3 Procedures for this meeting (Moderator) + +## 1.4 Approval of agenda + +## 1.5 Approval of previous minutes (Moderator) + +## 1.6 Review of action items and resolutions (Secretary Stefan) + +## 1.7 Identification of TC voting members (Secretary) + +### 1.7.1 Prospective voting members attending their first meeting + +### 1.7.2 Members attaining voting rights at the end of this meeting + +### 1.7.3 Members losing voting rights if they have not joined this meeting by the time it ends + +### 1.7.4 Members who previously lost voting rights who are attending this meeting + +### 1.7.5 Members who have declared a leave of absence + +# 2. Future Meetings + +## 2.1 Future meeting schedule (Secretary) + +# 3. Discussion + +## 3.1 Next steps + +# 4. Other Business + +# 5. Resolutions and Decisions reached (by 10 minutes prior to scheduled meeting end) + +## 5.1 End debate of other issues by 10 minutes prior to scheduled meeting end and follow the agenda from this point (Co-Chair) + +## 5.2 Review of Decisions Reached (Secretary) + +## 5.3 Review of Action Items (Secretary) + +# 7. Next Meeting + +# 8. Adjournment + +Meeting was adjourned. From a9ddca2d03f1b13ebf80df0ef50e84bb8028ba07 Mon Sep 17 00:00:00 2001 From: Justin Murphy <96064251+justmurphy@users.noreply.github.com> Date: Tue, 17 Dec 2024 10:49:39 -0500 Subject: [PATCH 13/19] add attendance for august meeting --- meeting-minutes/2024/2024-08-21.md | 38 ++++++++++++++++++++++++++++++ 1 file changed, 38 insertions(+) diff --git a/meeting-minutes/2024/2024-08-21.md b/meeting-minutes/2024/2024-08-21.md index 508b969..3856526 100644 --- a/meeting-minutes/2024/2024-08-21.md +++ b/meeting-minutes/2024/2024-08-21.md @@ -3,6 +3,42 @@ ## 1.1 Opening comments (Co-Chair) ## 1.2 Introduction of participants/roll call (Co-Chair) +Quorum requires participation of 9 or more of the 16 voting members (including the officers). + +| First Name | Last Name | Company | Role(s) | Present | +|:-----------|:-----------|:------------------------------------------------------------|:--------------------------|:--------| +| Adrian | Diglio | Microsoft | Voting Member | No | +| Altaz | Valani | Individual | Member | No | +| David | Kemp | National Security Agency | Member | No | +| Denny | Page | Individual | Voting Member | Yes | +| Duncan | Sparrell | sFractal Consulting LLC | Member | No | +| Feng | Cao | Oracle | Member | Yes | +| Harin | Sarda | Cisco Systems | Voting Member | Yes | +| Jay | White | Microsoft | Voting Member | Yes | +| Jeremy | Rickard | Microsoft | Member | No | +| Justin | Murphy | DHS Cybersecurity and Infrastructure Security Agency (CISA) | Co-Chair | Yes | +| Kris | Vandecruys | Cisco Systems | Voting Member | Yes | +| Kunal | Modasiya | Qualys, Inc. | Member | No | +| Langley | Rock | Dell | Voting Member | No | +| Martin | Prpic | Red Hat | Voting Member | Yes | +| Omar | Santos | Cisco Systems | Co-Chair | Yes | +| Pablo | Quiroga | Qualys, Inc. | Voting Member | Yes | +| Peter | Gephardt | IBM | Member | No | +| Przemyslaw | Roguski | Red Hat | Voting Member | Yes | +| Shridhar | Chari | Cisco Systems | Member | No | +| Sonny | van Lingen | Huawei Technologies Co., Ltd. | Voting Member | No | +| Stefan | Arntzen | Huawei Technologies Co., Ltd. | Voting Member | Yes | +| Stefan | Hagen | Individual | Secretary | No | +| Thomas | Proell | Siemens | Member | No | +| Thomas | Schaffer | Cisco Systems | Voting Member | Yes | +| Thomas | Schmidt | Federal Office for Information Security (BSI) Germany | Voting Member | Yes | +| Tobias | Limmer | Siemens | Member | No | + +Regrets: + +* Stefan Hagen + +Quorum was reached (12 voting members present) ## 1.3 Procedures for this meeting (Moderator) @@ -18,6 +54,8 @@ ### 1.7.2 Members attaining voting rights at the end of this meeting +* Feng Cao + ### 1.7.3 Members losing voting rights if they have not joined this meeting by the time it ends ### 1.7.4 Members who previously lost voting rights who are attending this meeting From 45d987d62340901219a6919c70df116aadf040a2 Mon Sep 17 00:00:00 2001 From: Justin Murphy <96064251+justmurphy@users.noreply.github.com> Date: Tue, 17 Dec 2024 10:56:02 -0500 Subject: [PATCH 14/19] add content for meeting minutes for august --- meeting-minutes/2024/2024-08-21.md | 40 ++++++++++++++++++++++++++++++ 1 file changed, 40 insertions(+) diff --git a/meeting-minutes/2024/2024-08-21.md b/meeting-minutes/2024/2024-08-21.md index 3856526..646a8f8 100644 --- a/meeting-minutes/2024/2024-08-21.md +++ b/meeting-minutes/2024/2024-08-21.md @@ -46,10 +46,16 @@ Quorum was reached (12 voting members present) ## 1.5 Approval of previous minutes (Moderator) +None (motions carried out already per e-mail motions). + ## 1.6 Review of action items and resolutions (Secretary Stefan) +n/a + ## 1.7 Identification of TC voting members (Secretary) +n/a + ### 1.7.1 Prospective voting members attending their first meeting ### 1.7.2 Members attaining voting rights at the end of this meeting @@ -62,16 +68,44 @@ Quorum was reached (12 voting members present) ### 1.7.5 Members who have declared a leave of absence +* Stegan Hagen + # 2. Future Meetings ## 2.1 Future meeting schedule (Secretary) + ``` + September 18, 2024 + October 16, 2024 (daylight saving times still active) + November 29, 2024 (normal time switch back done, same time on wall clock) + December 18, 2024 + January 15, 2025 + ``` # 3. Discussion +The meeting focused on creating definitions for end of sales and end of life, including the need for a generic definition that covers both hardware and software. + +* The team discussed creating a definition for software and hardware end of sales, and decided to use one broader definition that covers both scenarios. +* They identified the need to define the term "vendor" and discussed integrating the concept of "product family" into the schema. +* There was a suggestion to use "May" instead of "can" in the standard, and questions were raised about whether cloud services should be covered by open UX. +* There is a concern about random CNAs reporting vulnerabilities without discussing them with project maintainers. +* The definition of "vendor" is being discussed, including the need for an official list and entity claiming product IDs. +* The end of sales definition excludes open-source projects without sales, and downstream providers may have different end of sales dates. +* The definition of "end of sales" should include the last order date, which is more important for customers. +* When a company is acquired or changes ownership, they should update their open UX documents to reflect the change. +* The end of sales definition should apply to both software and hardware. +* There are two types of end of life: one where someone doesn't want to continue and one where they are unable to continue. +* The meeting discussed the need for a generic end of life definition that covers both hardware and software. +* The team agreed to remove the software part from the proposed definition and focus on a generic end of life definition. + ## 3.1 Next steps +* Keep on discussng on GitHub and mailing list + # 4. Other Business +None + # 5. Resolutions and Decisions reached (by 10 minutes prior to scheduled meeting end) ## 5.1 End debate of other issues by 10 minutes prior to scheduled meeting end and follow the agenda from this point (Co-Chair) @@ -80,8 +114,14 @@ Quorum was reached (12 voting members present) ## 5.3 Review of Action Items (Secretary) +None + # 7. Next Meeting + ``` + Sept 18, 2024 09:00 PDT / 12:00 EDT / 18:00 CEST / 16:00 UTC for 1 hour + ``` + # 8. Adjournment Meeting was adjourned. From d1c96b463b4153960e27c0c0ee20124ddca0f173 Mon Sep 17 00:00:00 2001 From: Justin Murphy <96064251+justmurphy@users.noreply.github.com> Date: Tue, 17 Dec 2024 10:59:01 -0500 Subject: [PATCH 15/19] add voting member info --- meeting-minutes/2024/2024-08-21.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meeting-minutes/2024/2024-08-21.md b/meeting-minutes/2024/2024-08-21.md index 646a8f8..d76c5a4 100644 --- a/meeting-minutes/2024/2024-08-21.md +++ b/meeting-minutes/2024/2024-08-21.md @@ -64,6 +64,8 @@ n/a ### 1.7.3 Members losing voting rights if they have not joined this meeting by the time it ends +* Langley Rock + ### 1.7.4 Members who previously lost voting rights who are attending this meeting ### 1.7.5 Members who have declared a leave of absence From 4ab98a2ac972ac69368a48ad5784ae99e159a7d1 Mon Sep 17 00:00:00 2001 From: Justin Murphy <96064251+justmurphy@users.noreply.github.com> Date: Wed, 18 Dec 2024 13:05:26 -0500 Subject: [PATCH 16/19] correct date for November meeting Co-authored-by: tschmidtb51 <65305130+tschmidtb51@users.noreply.github.com> --- meeting-minutes/2024/2024-08-21.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meeting-minutes/2024/2024-08-21.md b/meeting-minutes/2024/2024-08-21.md index d76c5a4..231d0ab 100644 --- a/meeting-minutes/2024/2024-08-21.md +++ b/meeting-minutes/2024/2024-08-21.md @@ -79,7 +79,7 @@ n/a ``` September 18, 2024 October 16, 2024 (daylight saving times still active) - November 29, 2024 (normal time switch back done, same time on wall clock) + November 20, 2024 (normal time switch back done, same time on wall clock) December 18, 2024 January 15, 2025 ``` From 375eb34edb981423fef80a65efaff176a707f7c1 Mon Sep 17 00:00:00 2001 From: Justin Murphy <96064251+justmurphy@users.noreply.github.com> Date: Wed, 18 Dec 2024 13:06:18 -0500 Subject: [PATCH 17/19] fix typos Co-authored-by: tschmidtb51 <65305130+tschmidtb51@users.noreply.github.com> --- meeting-minutes/2024/2024-08-21.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meeting-minutes/2024/2024-08-21.md b/meeting-minutes/2024/2024-08-21.md index 231d0ab..321d90f 100644 --- a/meeting-minutes/2024/2024-08-21.md +++ b/meeting-minutes/2024/2024-08-21.md @@ -89,7 +89,7 @@ The meeting focused on creating definitions for end of sales and end of life, in * The team discussed creating a definition for software and hardware end of sales, and decided to use one broader definition that covers both scenarios. * They identified the need to define the term "vendor" and discussed integrating the concept of "product family" into the schema. -* There was a suggestion to use "May" instead of "can" in the standard, and questions were raised about whether cloud services should be covered by open UX. +* There was a suggestion to use "MAY" instead of "can" in the standard, and questions were raised about whether cloud services should be covered by OpenEoX. * There is a concern about random CNAs reporting vulnerabilities without discussing them with project maintainers. * The definition of "vendor" is being discussed, including the need for an official list and entity claiming product IDs. * The end of sales definition excludes open-source projects without sales, and downstream providers may have different end of sales dates. From 32425d84889e6fb9952c507c177c491220149dd8 Mon Sep 17 00:00:00 2001 From: Justin Murphy <96064251+justmurphy@users.noreply.github.com> Date: Wed, 18 Dec 2024 13:08:26 -0500 Subject: [PATCH 18/19] edits to discussion item Co-authored-by: tschmidtb51 <65305130+tschmidtb51@users.noreply.github.com> --- meeting-minutes/2024/2024-08-21.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/meeting-minutes/2024/2024-08-21.md b/meeting-minutes/2024/2024-08-21.md index 321d90f..a850d5f 100644 --- a/meeting-minutes/2024/2024-08-21.md +++ b/meeting-minutes/2024/2024-08-21.md @@ -93,7 +93,8 @@ The meeting focused on creating definitions for end of sales and end of life, in * There is a concern about random CNAs reporting vulnerabilities without discussing them with project maintainers. * The definition of "vendor" is being discussed, including the need for an official list and entity claiming product IDs. * The end of sales definition excludes open-source projects without sales, and downstream providers may have different end of sales dates. -* The definition of "end of sales" should include the last order date, which is more important for customers. +- It was discussed whether the definition of "end of sales" should include the last order date, which might be more important for customers. + * When a company is acquired or changes ownership, they should update their open UX documents to reflect the change. * The end of sales definition should apply to both software and hardware. * There are two types of end of life: one where someone doesn't want to continue and one where they are unable to continue. From a8ebc9aeb15e9c19498802e8ce1ec30e0b634883 Mon Sep 17 00:00:00 2001 From: Justin Murphy <96064251+justmurphy@users.noreply.github.com> Date: Wed, 18 Dec 2024 13:08:45 -0500 Subject: [PATCH 19/19] fix typo OpenEoX Co-authored-by: tschmidtb51 <65305130+tschmidtb51@users.noreply.github.com> --- meeting-minutes/2024/2024-08-21.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meeting-minutes/2024/2024-08-21.md b/meeting-minutes/2024/2024-08-21.md index a850d5f..cb9c092 100644 --- a/meeting-minutes/2024/2024-08-21.md +++ b/meeting-minutes/2024/2024-08-21.md @@ -95,7 +95,7 @@ The meeting focused on creating definitions for end of sales and end of life, in * The end of sales definition excludes open-source projects without sales, and downstream providers may have different end of sales dates. - It was discussed whether the definition of "end of sales" should include the last order date, which might be more important for customers. -* When a company is acquired or changes ownership, they should update their open UX documents to reflect the change. +* When a company is acquired or changes ownership, they should update their OpenEoX documents to reflect the change. * The end of sales definition should apply to both software and hardware. * There are two types of end of life: one where someone doesn't want to continue and one where they are unable to continue. * The meeting discussed the need for a generic end of life definition that covers both hardware and software.