Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Evaluation Criteria for funding initiatives #11

Open
nellshamrell opened this issue Aug 18, 2023 · 1 comment
Open

Evaluation Criteria for funding initiatives #11

nellshamrell opened this issue Aug 18, 2023 · 1 comment

Comments

@nellshamrell
Copy link
Contributor

One of our next actions will be recommending specific initiatives related to memory safety for the OpenSSF (and its members) to fund.

Example: Prossimo

I'd like us to start brainstorming how we might evaluate initiatives for funding.

Criteria may include:

  • Is this initiative related to memory safety specifically?
  • How does this initiative impact memory safety in Open Source software?
  • How can this impact be measured?

What else should we include?

@GabrielDosReis
Copy link

What else should we include?

  • Practicality at scale
  • If a tool, how widely available?
  • If programming practice, how is it enforced? Any downsides?
  • How do we measure adoptability?
  • Static analysis code techniques aim to prevent bad things before they happen; how to actually measure success when "no bad things" happen? How to draw a direct link from those techniques to absence of an event therefore absence of evidence?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants