Skip to content

Access continuity - #179

Open
degenaro wants to merge 5 commits into
mainfrom
access-continuity
Open

Access continuity#179
degenaro wants to merge 5 commits into
mainfrom
access-continuity

Conversation

@degenaro

@degenaro degenaro commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

re: https://www.bestpractices.dev/en/projects/9408/silver/

  1. The project MUST be able to continue with minimal interruption if any one person dies, is incapacitated, or is otherwise unable or unwilling to continue support of the project. In particular, the project MUST be able to create and close issues, accept proposed changes, and release versions of software, within a week of confirmation of the loss of support from any one individual. This MAY be done by ensuring someone else has any necessary keys, passwords, and legal rights to continue the project. Individuals who run a FLOSS project MAY do this by providing keys in a lockbox and a will providing any needed legal rights (e.g., for DNS names). (URL required) [access_continuity]

  2. The project SHOULD have a "bus factor" of 2 or more. (URL required) [bus_factor]
    A "bus factor" (aka "truck factor") is the minimum number of project members that have to suddenly disappear from a project ("hit by a bus") before the project stalls due to lack of knowledgeable or competent personnel. The truck-factor tool can estimate this for projects on GitHub. For more information, see Assessing the Bus Factor of Git Repositories by Cosentino et al.

Signed-off-by: degenaro <lou.degenaro@gmail.com>
Signed-off-by: degenaro <lou.degenaro@gmail.com>
Signed-off-by: degenaro <lou.degenaro@gmail.com>
@degenaro

degenaro commented Sep 4, 2026

Copy link
Copy Markdown
Contributor Author

/vote-super

@git-vote

git-vote Bot commented Sep 4, 2026

Copy link
Copy Markdown

Vote created

@degenaro has called for a vote on Access continuity (#179).

The members of the following teams have binding votes:

Team
@oscal-compass/oversight-committee-members

Non-binding votes are also appreciated as a sign of support!

How to vote

You can cast your vote by reacting to this comment. The following reactions are supported:

In favor Against Abstain
👍 👎 👀

Please note that voting for multiple options is not allowed and those votes won't be counted.

The vote will be open for 28days. It will pass if at least 66% of the users with binding votes vote In favor 👍. Once it's closed, results will be published here as a new comment.

@git-vote

git-vote Bot commented Sep 9, 2026

Copy link
Copy Markdown

Vote closed

The vote passed! 🎉

66.67% of the users with binding vote were in favor and 0.00% were against (passing threshold: 66%).

Summary

In favor Against Abstain Not voted
4 0 0 2

Binding votes (4)

User Vote Timestamp
@ancatri In favor 2026-09-08 18:40:40.0 +00:00:00
@degenaro In favor 2026-09-04 13:47:31.0 +00:00:00
@vikas-agarwal76 In favor 2026-09-05 3:14:19.0 +00:00:00
@yuji-watanabe-jp In favor 2026-09-08 6:00:57.0 +00:00:00

@degenaro

degenaro commented Sep 9, 2026

Copy link
Copy Markdown
Contributor Author

Access Continuity Explanation for OpenSSF Best Practices [access_continuity]

The project satisfies the access continuity requirement through shared organization administration, distributed maintainership, and documented governance procedures:

  1. Multi-Admin and Multi-Org Redundancy: Administrative access, credentials, and repository rights across the oscal-compass organization are shared among multiple Org Admins from different member organizations, plus a Linux Foundation backstop account (thelinuxfoundation). This ensures that operations (managing issues, merging pull requests, releasing software) can proceed without disruption if any single person is lost.
  2. Succession and Vacancy Rules: Formal vacancy appointment and governance policies allow the multi-member Oversight Committee to reallocate responsibilities and maintain uninterrupted project continuity within one week.

Reference URLs

@degenaro

degenaro commented Sep 9, 2026

Copy link
Copy Markdown
Contributor Author

OpenSSF Silver — bus_factor Justification
Project: OSCAL Compass · Criterion ID: bus_factor

Criterion
The project SHOULD have a bus factor of 2 or more.
URL
https://github.com/oscal-compass/community/blob/main/GOVERNANCE.md#access-continuity
Justification
OSCAL Compass maintains a bus factor of 2 or more. The project's Access Continuity governance section documents that no single person is a point of failure. A six-member Oversight Committee drawn from at least three independent organizations (IBM, Red Hat, Sunstone Secure) collectively holds all necessary repository access, credentials, and legal rights. Multiple Org Admins — including a Linux Foundation backstop — ensure continuity of operations. Project knowledge is actively distributed across contributors from different organizations, so the project can continue to function within one week of losing any individual contributor. Vacancies are filled by appointment per the documented Vacancies process.

@vikas-agarwal76 vikas-agarwal76 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants