Rules of Engagement for Forking a Dependency (SOSS Community Day Europe 2024)

cpswan 10 views 20 slides Sep 19, 2024
Slide 1
Slide 1 of 20
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8
Slide 9
9
Slide 10
10
Slide 11
11
Slide 12
12
Slide 13
13
Slide 14
14
Slide 15
15
Slide 16
16
Slide 17
17
Slide 18
18
Slide 19
19
Slide 20
20

About This Presentation

You got the CVE notification, but there's no fix yet. Customers GUACing your SBOMs are worried. Should you fork? This presentation will run through the rules of engagement we've used at Atsign when these situations arise, which aim to balance good community citizenship with making sure stuff...


Slide Content

© 2024 - Atsign | docs.atsign.com
Rules of Engagement for
Forking a Dependency
SOSS Community Day Vienna - Sep 2024
CC BY 2.0 image by i_yudai

© 2024 - Atsign | docs.atsign.com

© 2024 - Atsign | docs.atsign.com
https://xkcd.com/2347/

© 2024 - Atsign | docs.atsign.com
Hi, I’m Chris
@cpswan
https://chris.swanz.net

© 2024 - Atsign | docs.atsign.com
The steps
1.Check to see if there’s already an issue (or PR)
2.Raise an issue
3.Submit a PR
4.Fork the repo and publish a variant

Rules of Engagement?
https://en.wikipedia.org/wiki/Rules_of_engagement

1.Check first
??????

2. Raise an issue

3. Raise a PR

4. (Reluctantly) Fork (and publish a variant)

© 2024 - Atsign | docs.atsign.com
The steps
1.Check to see if there’s already an issue (or PR)
2.Raise an issue
3.Submit a PR
4.Fork the repo and publish a variant

Resources
Blog post:
https://blog.atsign.dev/steps-before-forking

Thanks for your time
[email protected]
@cpswan

Questions?