►
From YouTube: Education SIG (February 22, 2023)
Description
Agenda – https://docs.google.com/document/d/18GBwvQJNcPnwxKrnp43DhBZC7K1JM0xzGkDoKh5mu8U/edit#
Slack – https://openssf.slack.com/archives/C03FW3YGXH9
Mailing List – https://lists.openssf.org/g/openssf-sig-education
Git Repo - https://github.com/ossf/education
A
Another
do
out
as
well
I'm
imagining
we
want
to
talk
about
that
as
a
Sig,
but
though
I
know
those
two
things
were
talked
about
the
same
week.
So
so
we
kept
we
gotta
drill
down
on
those
yeah.
B
B
All
right,
that's
it
for
today
at
least
thank
you.
They
are
sure
they're
lost
their
souls,
I
guess
how
did
you
join,
but
this
meeting.
A
C
Hi
yeah
I,
just
I,
didn't
even
see
that
it
was
being
canceled
but
yeah
I
kind
of
wanted
to
happen.
Since
it's
been
a
really
long
time.
C
Yeah,
so
are
these
meetings
happening
weekly
now?
It
seems
like
most
of
the
time
right.
A
Oh
yeah,
the
opposition
means
a
happening
weekly,
but
this
meeting
time
is
going
to
change
a
couple
of
meetings
ago.
We
voted
on
having
the
meeting
at
an
earlier
time.
C
A
But
I
believe
that,
but
and
also
at
the
working
group
meeting,
we
decided
to
uplevel
the
meeting
having
it
as
like
an
S2,
c2f
and
salsa
positioning
meeting
so
earlier
time,
and
also
the
the
scope
of
the
meeting
is
going
to
change
as
well.
All
things
to
stay
tuned
up
but
yeah.
The
meanings
for
today
is
has
got,
has
gotten
gotten
canceled.
C
All
right,
yeah,
that's
fine,
yeah,
I'll
I'll.
Just
try
to
keep
an
eye
out
for
for
the
updates,
then
yeah.
A
And
I
saw
that
you
that
you
wanted
to
have
your
name
added
to
the
blog
post,
make
sure
you
get
on
that
get
on
in
that
blog
and
do
some
comments
and
stuff
as
well.
C
Yeah
I
did
I
did
leave
some
comments.
I,
don't
necessarily
need
to
have
my
name
added.
I
thought
it
was
mostly
for
commenting,
but
yeah
yeah
it.
For
now
it
looks
like
it's
mostly
going
to
be.
Mark
and
Chris
are
going
to
be
the
authors
yeah.
A
And
now:
well,
that's
what
it
says:
I'm
not
I'm,
not
terribly
sure,
I'm,
not
terribly
sure
what
the
shape,
how
that's
going
to
shake
out
completely
but
yeah.
That's
definitely
what
it
says.
C
Oh
I
totally
misread
that.
Oh
wait,
yeah
I,
don't
know
if
they
changed
it.
C
A
Says
I
don't
know
yeah
it
has
Mark's
name
and
Mark
and
Mark
said,
oh,
the
great
great
that
my
name
is
here.
I,
just
don't
want
to
be
here
by
myself.
A
Well,
my
thought
my
thoughts
are
are
as
I
comment
as
I
comment
regularly
man
we
doing
when
it
comes
to
salsa
we're
doing
a
lot
of
before
the
horse
type
stuff.
C
A
C
A
And
and
the
work
like
when
it
comes
to
a
spec,
you
don't
have
many
opportunities
to
change
when
it
becomes
public.
You
don't
have
many
opportunities
to
change
the
scope
of
the
spec,
because
then
it
stops
being
a
specification
yeah.
It
starts
just
being
a
a
great
idea
like
you
like
it
it
it's
a
great
idea.
That
becomes
a
specification
when
it's
adopted,
but
if
you
keep
changing
the
scope
of
it,
you're
not
going
to
get
much
adoption
and
the
people
who
have
adopted
it
and
then
be
like
dude.
A
B
A
A
We
need
to
you,
know,
you're,
making
some
bold
statements
on
stuff
that
ain't
done
yet,
and
you
know
just
just
the
the
just
the
fact
alone
that
you
have
some
people
that
say
that
they've
adopted
salsa
well,
I,
don't
know
what's
hot,
with
salsa
you're
adopting,
because
things
have
been
split
off
into
four
or
five
different
tracks,
which
track
did
you
adopt
because
the
last
time
I
checked
we're
not
even
on
version
one
yet,
and
that
is
the
build
track.
It
ain't
nothing
else.
Yeah.
B
C
Yeah,
no
even
one
of
the
comments
that
I
left
kind
of
towards
the
bottom
of
the
of
the
document,
or
just
like-
oh,
are
you:
are
we
actually
in
support
of
the
division
I
was
like?
Are
we
implying
that
we're
gonna
reverse
some
of
our
to
your
point
about
it
changing
too
often
well,.
A
A
C
A
Been
a
lot
more
yeah,
you
were
one
of
the
people.
That
said
well.
What
providence
are
we
talking
about,
because
open
source
provenance
is
one
thing
that
all
that
means
is
that
you
can
trace
open
source
component
back
to
its
original
Source,
like
you
can
trace
it
back
you,
you
know
where
it
came.
A
A
I
mean
like
Isis
out
there.
You
should
see
I
when
I
saw
I
was
like
who
I
was
like.
Where
did
the
conversation
about
s-bomb
versus
salsa
Province
and
they
were
like
Jay?
Please
don't
get
started,
don't
they
shut
up
because
I,
because
I
came
in
on
the
tail
end,
it
was
like
they're
like
Jay.
We
please,
please
don't
bring
that
back
up.
Just
I
was
like
what
the
hell
I
couldn't
believe
it
I
was
like
what
are
they
talking
about?
Oh
thank
you,
but
that's
the
kind
of
stuff
that's
happening.
A
You
know
that's
concept,
that's
happening
behind
the
scenes
that
we
don't
hear
about
until
it
comes
up
and
a
lot
of
this
stuff
I
mean
like
look
I
I
I've
said
before
I'm.
Like
you
know,
you
know:
okay,
I
I,
don't
I'm
not
terribly
sure
how
the
scope
of
salsa
keeps
changing
and
that's,
and
once
again
in
that
blog
I
said
the
same
thing.
I
said
we
got
to
be
careful
about
scope
creep
here.
The
scope
of
salsa
has
changed
like
three
or
four
times
since.
A
C
A
I
I
mean
look,
I
still
think
it's
a
I
still
think
it's
a
good
effort,
I
think
it's
a
good
effort.
I
think
the
right
people
in
the
room
to
talk
about
it
and
help
fix
and
help
get
it
moved
along
and
then
do
all
that
kind
of
stuff.
I.
Just
think
that
that
we
need
to
make
a
decision
on
something
and
stick
with
it
so
that
we
can
get
to
a
1.0
I
think
that's
preventing
us
from
1.0.
A
A
It
was
canceled,
Marcella
and
I.
Just
are
just
talking
about
the
catching
up.
Okay,
I
have
not
been
here
for
the
last
few
minutes,
catching
up
a
bit.
C
B
Working
kind
of
an
intersection,
so
yeah,
okay,
yeah
I'm,
working
on
the
Salsa
Salsa,
like
components
of
spdx
and
again
I
want
to
clarify
spdx
is
not
equals
as
home
as
a
part
of
spdx.
So
there's
also
the.
A
Mean
look
at
that,
so
that
argument
in
the
in
the
in
the
conversation
is
is
is
extremely
extremely
important
because
of
that
small
bit
of
confusion
around
what
spdx
you
know
actually
is
in
relation
in
relation
to
to
salsa.
A
You
know
it's
it's
just
it's
just
a
it's
just
a
a
form
of
of
writing
of
writing.
S-Bombs!
It's
not
it's!
Not
it's
not
a
it's!
Not
it's!
It's
a
form
of
it's
a
form
of
a
written
s-bomb,
but
it's
not
I
mean
I
I.
Don't
know
that
like
a
lot
of
these
conversations
are
a
lot
of
these
conversations.
Are
a
real
man,
we're
like
late
in
the
game
to
be
having
a
lot
of
these
conversations.
A
A
We're
talking
about
1.0,
you
shouldn't
be
trying
to
adjudicate
what
is
or
isn't
an
s-bomb
I,
don't
even
know
like
what
what
what
is
I'll
I'll,
Soap
Box
again,
if
I
do
that,
I'll
sell
Buckskin
I,
don't
want
to
do
it
all
I
want
to
do
with
reflected
with
respective
positioning
is
make
sure
that
we're
telling
the
story
and
telling
it
correctly
and
telling
it
the
right
way,
the
first
time
and
not
having
to
to
to
retract
all
the
time.
B
Yeah
I
I
think
I
have
I,
don't
know
what
what
what
the
group
has
been
up
to,
but
I
would
be
happy
to
have
like,
at
least
from
the
SPD
aspect.
Perspective
like
write
a
write,
a
blog
post
on
the
salsa
blog
to
kind
of
like
Define,
that
if
that's
helpful,.
A
I
mean
at
our
next
positioning
meeting,
because
I
think
I
think
it
might
be
relevant
for
both
salsa
and
s2c2f,
especially
if
we
do
up
level
the
positioning
meeting
to
salsa
and
S2
c2f
they'll
talk
about
spdx
because
you
know
I,
don't
want
to
say
most
s-bomb
generating
tools,
but
the
good
majority
of
s-bomb,
generating
to
their
app
I
mean
at
least
the
ones
being
developed
today
are
using
spdx
to
generate
s-bombs
and
that's
just
because
of
EO
compliance,
and
all
that
kind
of
stuff,
as
PDX
is
a
is
a
as
an
ISO
is
an
ISO
spec.
A
Currently
that
meets
EO
that
meets
EO
compliance.
You
know
for
for
helping
to
write
Xbox,
so
most
generated
tools
are
using
spdx
to
write
them.
A
It
would
be
good
for
you
to
do
that,
but
that
would
mean
that
that,
for
salsa
purposes
and
even
for
for
s2c2f
that
we'd
be
saying
S
no
spdx
is
the
spdx
is
what
we're
going
to
be
using
to
write
ass
bombs
and
I'm,
not
sure
if
you
want
to
I'm,
not
sure
if
we
want
to
pigeonhole
into
one
technology
because
I
don't
know
I'm,
just
saying
I'm,
not
sure
if
we
want
to
pigeonhole
into
that
one
technology
to
write
s-bombs
versus
maybe
something
that
maybe
having
a
versatility
or
being
able
to
use
it
at
that
spawn
written
in
any
written
in
any
any
standard
or
whatever
is,
is
a
nest
bomb
right?
A
B
Yeah
yeah
I
mean
that's
still
foaming
up,
so
no
one
really
knows
what
the
execution
of
the
the.
A
A
Exactly
I
mean,
like
all
things
that
are
still
up
in
the
air
right
I
mean
like
you
know
what
what
is
the
and
that
and
that's
a
big.
That's
a
large
part
of
this
too.
A
large
part
of
this
is
the
ambiguity
and
and
I
guess
we
work
through
you
know
so
so
that
that's
why
I
say
I
mean
I,
don't
know
about
a
a
Blog
that
just
talks
about
spdx
in
relation
to
to
salsa
I.
Think
that
we
do
need
to
have
a
discussion
and
then
see
where
we
want
to
go.
B
B
Stay
tuned,
whatever
that's
going
to
be
posted,
so
I,
know
maybe
Charming
on
that
cool,
all
right,
I'm,
sorry
to
budget
and
I'll
leave
you
all
the
chat.
C
Too
thanks
yeah
I'm,
probably
gonna
head
out
in
a
bit
too
I'm,
probably
gonna
head
out
in
just
a
bit
too
yeah
So,
based
on
what
Brandon
was
saying.
That
was
kind
of
an
interesting
point.
C
A
A
A
It
includes
bird
no
stuff
from
Virgin
Providence
version,
0.1
I
might
do
that's
that
is,
you
know,
I
mean
so
so
I
that
being
the
case,
I
I,
don't
I
think
that
no
I
I
don't
I,
don't
because
I
think
to
even
introduce
an
argument
about
it's,
not
an
s-bomb
I
think
to
even
do
that
creates
more
questions
than
it
does
answers
Fair
right,
oh
yeah!
If
you
have
to
go
out
and
say,
salsa
is
not
an
s-bomb
well.
A
Why
is
that
even
a
conversation
to
begin
with,
let's
look
deeper
into
any
similarities
or
or
differences,
and
now
you're
saying
well?
Why
would
they
even
mention
you
know
I
mean
like
it
creates
it
creates
more
that
that
was
my
whole
thing
about
salsa
Providence
and
that's
what
I'm
like?
Why
would
you
even
do
that
like
yeah
like
and
that's
Barbara's
Nest
bomb,
it's
also
Providence
South,
but
why
would
you
even
put
those
two
together
and
say
verses?
Why
would
you
even
put
a
verses
in
there.
C
A
Mean
s-bomb
versus
salsa,
probably
why
would
you
even
do
that
like
that,
like
that,
like
what?
What
doesn't
even
make
any
sense
to
me,
but
so
so
I
would
say:
no,
no,
no
don't
even
they
played
this.
An
s-bomb
should
help
meet
certain
salsa
requirements.
Sure,
but
but
I
think
for
the
purposes
of
that
blog,
that
that's
not
that's,
not
something
you
would
mentioned
in
that
blog
unless
it's
somewhere
benefits
of
the
build
track.
A
C
Yeah
yeah
I
I've
noticed
not
just
not
just
even
in
the
salsa
meetings
but
internally
and
talking
to
other
folks
in
other
communities.
There's
still
a
lot
of
the
sort
of
opposing
mentality
of
like
I
mean
people
have
asked
me
like
Why
Can't,
This
Be,
instead
of
an
s-bomb,
that's
not
when
s-bomb
is
for
and.
C
A
C
A
Happens
next
document
exactly
right
and
then
you
know,
there's
a
there's,
a
a
large
contingent.
That
is
still
unaware
of
what
these
things
actually
are,
what
they're
actually
used
for
and
then
there
are
a
lot
of
people
who
there
are
a
lot
of
different
thoughts
around
an
s-bomb
and
what
an
s-bomb,
and
then
you
have
P
bombs
and
e-bombs
and
yeah
all
kinds
of
bombs.
I
I
mean
it's
like
they.
We
didn't
even
get
s-bomb
out
the
door.
Yet
before
now
you
got
all
these
other
bombs.
Yeah.
A
It's
hilarious,
I
I,
sit
back
and
I
laugh
about
it,
but
all
an
s-bomb
is:
is
the
ingredients
of
your
software
build
yeah?
That's
it
that
that
is
it
there's
there's!
No,
there
is
no
salsa.
A
There
is
nothing
else
there
other
than
the
ingredients
of
your
build
and,
and
all
that
will
do
is
help
you
prioritize
vulnerability,
vulnerability.
Remediation
should
a
fixed
document
tell
you
that
there
is
a
component
that
was
used
that
is
affected
by
a
certain
vulnerability.
Now
you
have
to
go
into
your
s-bomb
identify
which
component?
That
is,
if
it's
there,
the
version
number
Etc,
is
it
vulnerable?
Is
it
not
vulnerable?
Okay?
A
C
Yeah,
no,
it's
it's
yeah.
Definitely
not
yeah
I!
Think
my
fear
is
it's
gonna
come
up
again,
I've
been
a
lot
more
involved
in
this
on
the
specification
side
lately
and
there's
fields
in
the
salsa
Providence.
C
Now
that
are
basically
like
a
mini
s-bomb
like
that's
kind
of
what
they
amount
to,
because
that's
here's,
here's
the
dependencies
we
use
and
here's
the
hash
of
the
dependency
and
they
list
that
and
so
I
I
think
some
people
are
going
to
look
at
that
and
be
like
well
how's,
this
different
from
s-bomb
because,
like
what
you're
saying
like
they
don't
understand
the
the
differences
so.
C
Yeah
all
right,
while
I
have
you
here,
I
wanted
to
ask
you
about
something
entirely
different,
that
I've
been
meaning
to
reach
out
to
you
about
I'm,
organizing
a
workshop
in
November
with
some
other
folks
and
we're
looking
for
people
to
review
like
talk
abstracts.
C
A
Yeah
and
I
got
you
I'll
even
put
on
my
doctor
hat,
for
it.
C
Perfect
yeah
yeah!
No
thanks!
So
much
I'll
I'll,
send
you
the
the
official
like
invite
but
yeah
cool
cool
thanks
so
much
it.