►
From YouTube: SLSA Biweekly (December 15, 2022)
Description
Meeting notes: https://docs.google.com/document/d/1cx3fOBfic6A0xc2on25ITK4vQHUdxgBmJoSS1LPqDJo/edit
A
A
A
A
Yeah
I
forget
who
usually
drives
this
meeting.
I
missed
the
last
one
because
it
wasn't
on
my
calendar.
I
forgot
that
we
had
changed
it
to
monthly.
B
Usually
it's
like,
like
mic
or
camera,
you.
A
This
morning
to
facilitate
today,
I
did
not
know.
Okay,
never
mind.
I
just
saw
the
the
message
right
now,
so
I
guess
I
will
I
will
host.
Give
me
one
second,
so
never
mind.
Never
mind.
I
saw
mark,
asked
me
to
host
foreign.
A
Yeah,
okay,
so
I
guess
we'll
we'll
go
ahead
and
get
started.
Apologies
folks,
I,
didn't
look
at
my
slack
messages
before
the
meeting,
so
I
didn't
notice
that
I
was
supposed
to
be
hosting
the
call
so
welcome
everyone.
A
This
is
the
monthly
meeting
for
the
salsa
community
for
folks
that
are
new
and
don't
have
access.
Please
do
sign
in
I'm
posting
it
again.
Just
in
case
you
don't
have
access
to
the
document
is
anyone
new
to
the
group
and
if,
yes,
we
usually
give
time
for
the
new
folks
to
introduce
themselves
and
can
I
give
us
a
little
intro
about
you
and
and
what's
interesting
about.
What's
also
for
you.
D
Well,
yeah
I
could
start
and
I
apologize.
Cygnus
is
running
through
my
household
as
well,
so
I'm
gonna
lose
my
voice.
Forgive
me,
my
name
is
Jeff
I'm
from
Sunnyside
work
on
the
devrel
team,
with
Teresa
here,
I've
been
involved
in
openssf.
The
best
practices
in
education
groups
also
got
introduced
to
the
end
user
group
and
the
S2
c2f
Group,
which
talked
a
bit
about
salsa,
sometimes
involved
in
the
software
supply
chain,
stuff,
so
sort
of
want
to
understand
the
best
practices
of
mature
building.
D
As
far
as
the
framework
goes,
some
messages
just
here
to
learn
if
I
can
contribute
in
any
way
happy
to.
C
Yep
I'm
new
as
well
also
A,
co-worker
of
Jeff's
I'm,
a
developer
advocate
I'm
at
soda
type
and
yeah
I'm,
really
just
looking
for
ways
to
get
involved,
particularly
interested
in
hearing
about
tooling
I've
kind
of
been
in
contact
with
some
projects
that
are
are
using
salsa
as
well
so
scarcity
here.
What's
new
I
guess.
A
No
okay
well
again
welcome
to
the
new
members.
If
you
have
any
questions
about
some
of
the
the
sigs
for
the
salsa
working
group,
I'm
more
than
happy
to
walk
you
through
that,
let
me
share
my
my
screen.
A
Trying
to
share
so
okay
share,
okay.
Well,
let
me
share
my
screen
so
I'm
not
sure
why
it's
failing,
but
I'm,
just
working
from
the
meeting
notes.
Normally,
we
have
updates
from
the
six
six
are
basically
smaller
parts
of
salsa.
There's
a
specification
group
that
works
on
the
requirements
of
salsa.
A
Essentially,
you
know
what
does
it
mean
to
be
salsa
level,
one
two,
three
four
making
sure
that
it's
clearly
defined.
If
we
need
to
Pivot
because
of
you
know,
maybe
new
requirements,
that's
the
specification
group.
They
try
to
make
sure
that
we
are
moving
forward.
The
positioning
group
is
more
about
telling
the
world
you
know
what
salsa
is.
A
You
know
how
it
can
help
the
different
organizations
be
better
in
terms
of
supply,
chain
security
and
then
the
tooling
working
group,
which
is
held
hosted
by
Mike,
Lieberman
and
I
forgot
specification,
is
Mark
lodato
and
I'm,
forgetting
the
second
gentleman's
name
from
VMware
right
now,
I
can't
I
can't
remember
his
name,
Josh
Josh
there
you
go
Josh,
sorry,
and
so
the
tooling
really
is
more
probably
what
you're
interested
in
Teresa,
but
obviously
anyone
can
join
any
one
of
these
meetings.
A
I
believe
all
three
of
these
have
weekly
meetings
at
different
time.
Specifications
on
Monday,
positionings
on
Tuesdays
and
tooling,
is
on
Fridays,
so
just
wanted
to
give
you
a
a
lay
of
the
land
so
to
speak,
so
we
don't
have
an
update
for
specification
or
tooling.
Today,
I
suspect,
I
know
one
person
is
sick,
our
family
is
sick
and
then
the
other
person
I
might
be
out
on
vacation.
So.
B
B
So
we've
been
kind
of
collaborating
in
those
Chris.
K
has
a
really
interesting
document
that
we're
kind
of
collaborating
on
and
making
comments
around
verification
of
build
systems.
So
that's
kind
of
like
the
bigger
piece
within
the
spec
Community
or
taking
off
the
rest
of
the
year
rejoining
back
in
January
for
the
next
meetings.
After
that.
A
C
A
Okay,
so
for
positioning
somebody
reached
out
wanting
to
have
a
landing
page
for
salsa
inside
the
open
ssf
domain.
A
It's
not
supposed
to
be
a
replacement
for
the
salsa.dev
and
they
gave
an
example
of
the
six
door
Community
as
an
example
there
in
the
document
where
the
notes
are,
if
you
click
on
the
link,
the
open
ssf.org
has
a
landing
page
for
six
door
and
she
helped
create
that
and
she's
basically
reaching
out
to
want
wanting
to
do
the
same
for
salsa
and
we
felt
like
it
was
part
of
the
domain
of
the
positioning
group.
A
But
we
don't
know
who
created
the
salsa.dev
website
and
we
wanted
input
on
who
we
should
be
working
with.
To
make
sure
that
you
know
the
person
behind
is
also
that
Dev
kind
of
also
has
input
so
I'm,
not
sure.
If
folks
on
the
call
know
who
we
should
be
working
with.
But
we
are
more
than
happy
to
take
on
the
work
with
Tracy
to
to
do
that.
Landing.
Page
foreign.
B
I
think
Mark's
going
to
be
the
best
for
at
least
a
historical
context
around
the
website.
C
A
So
I'll
reach
out
to
him
for
that,
and
then
the
other
item
I
have
on
the
list.
A
I
I've
mentioned
it
for
the
supply
chain,
Integrity
working
group,
which
is
the
parent
of
this
I,
guess,
Sig
I,
don't
know
what
to
call
salsa,
because
it's
underneath
the
supply
chain,
Integrity
working
group,
and
then
we
have
six
under
salsa,
but
essentially
trying
to
understand
like
the
road
map
for
salsa
for
2023
right,
and
the
reason
why
this
came
up
in
positioning
is
because
we
said:
okay,
how
can
we
be
better
in
2023
and
some
of
the
concerns
that
came
up
were
well?
A
The
Providence
got
split
up
in
the
specification
for
1.0
and
so
we're
trying
to
figure
out
okay.
We
need
to
be
more
coordinated
in
salsa,
but
we
also
need
to
be
more
coordinated
in
the
supply
chain,
Integrity
working
group
across
the
different
subgroups,
Fresca
salsa
and
the
s2c2f,
and
so
yesterday
we
agreed
that
we
do
need
a
priority
and
kind
of
coordination
across
the
different
subgroups
for
supply
chain
integrity
and
then
once
we
have
that
priority,
I,
I,
think
or
the
prioritization,
and
what
we're
trying
to
accomplish
in
2023
I.
A
Think
salsa
itself
also
needs
that
roadmap,
so
that
the
the
tooling
positioning
and
the
specification
all
work
together.
A
They
all
kind
of
have
a
representative
talking
to
the
other
groups,
because
otherwise
we
might
you
know
not
realize,
what's
happening,
especially
when
you
think
about
sicknesses,
or
some
of
the
main
leads
doing
most
of
the
work
behind
the
scenes
and
they
and
they
might
not
be
able
to
attend
a
meeting
as
an
example
for
some
of
the
other
cigs.
A
So
really,
there
needs
to
be
tighter
collaboration,
I
think
between
the
Sig
leads
for
salsa,
but
then
also
trying
to
make
sure
that
we're
marching
to
the
same
beat
of
the
drum
for
2023,
so
that
we
can.
You
know
get
more
done
and
you
know
again
just
make
it
better
overall.
So
I'm
not
sure
if
there
are
comments
or
questions.
A
So
I'll
try
to
bring
this
up
again
in
the
next
meeting
right
up
again
and
next
meeting,
since
this
is
a
lighter
meeting,
but
that's
just
kind
of
a
a
heads
up
that
I'm
hoping
to
have
more
coordination
between
the
different
sigs
so
that
we
can
at
least
from
the
positioning
side.
We
can
be
more
productive
because,
right
now,
it's
very
difficult
when
things
are
not
supposed
to
be
changing
without
us.
Realizing
and
Asura
did
have
a
five
minute
agenda,
but
I
don't
see
Asura
on.
A
Does
anybody
know
if
Oscar
is
going
to
join
or
if
this
is
intended?
For
the
next
conversation,
foreign.
A
E
Yeah
hi,
so
I
guess
this
kind
of
is
similar
to
the
question
you
ask
about
priorities
and
how
we
better,
educate
or
like
inform
the
outside
community.
So
I
wanted
to
throw
an
idea.
I
wanted
to
have
some
feedback
and
opinion
on
whether
there's
a
need
for
also
having
some
sort
of
priorities
on
which
conferences
we
should
attend
and
talk
about
salsa
and
whether
we
should
have
a
salsa
conference
like
something
similar
to
the
sixth
law
conference.
Would
that
be
useful?
E
I
just
wanted
to
have
some.
You
know
some
reactions
see
what
people
think
in
general
about
this
line
of
this
direction.
A
Yeah
I
do
have
a
question
or
a
comment.
So
I
see
you
wrote
salsa
Khan,
I
I,
you
know
I,
guess
that
would
be
the
first
ever
salsa
con.
But
what
about
the
open
source?
Summit
I
know.
There's
open
ssf
day
there
and
I
know
a
lot
of
salsa
people
go
to
that
conference.
E
Yeah
I
guess
the
same
question
would
be
like.
Why
is
six
token
not
part
of
the
policy
safe,
Summit
I
think
I've
heard
that
the
open,
ssf
Summit
might
not
happen
next
year.
So
you
know,
I
haven't
talked
to
everyone
involved,
but
I
think
they
are
discussing
whether
they
want
to
have
that
Summit
yeah,
so
I
you're
right
it
would
be
the
first
salsa
Cohen
I
I.
Don't
have
an
answer
of.
Why
not
I
guess
the
open.
Ssf
Summit
is
mostly
for
open,
ssf
members.
E
But
if
you
want
to
reach
a
broader
audience,
maybe
we
need
something
more
dedicated,
I,
don't
know
you
could
have
something
at
RSA.
If
you
want
to
Target
CSO
things
like
this
or.
A
E
Could
have
a
track
in
a
more
like
software,
open
source
software
developer
conference,
something
like
first
Dem
I,
think
the
deadline
has
passed
but
I
guess
this
kind
of
discussion,
I
wonder
where
it's
happening
I
mean
who
would
be
interested
in
you
know,
looking
into
it,
I
mean
I
would
be
interested,
but
I'd
like
to
know
I'd
like
to
see
what
people
think
first,
because
it
takes
some
effort
so
and
I,
don't
know
where
it
falls
in
the
priority
list
that
you
mentioned
earlier.
Yeah.
B
I
think
this
is
a
great
idea
to
try
to
create
some
sort
of
you
know:
focus
on
salsa,
some
more
especially
in
23,
right
in
theory,
right
within
2023,
we'll
have
the
1.0
spec
out,
hopefully
right,
and
that
would
be.
B
That
would
be
like
the
key
right
like
we
could
have
it
kind
of
as
the
centerpiece
of
of
salsa
con
right
so
like
obviously,
it
probably
wouldn't
be
a
standalone
Conference,
of
course
right
so
like
attaching
to
to
one
of
those
well
attended
ones,
already
kind
of
like
Sig
storycon
had
been,
which
I
think
that
seemed
like
a
good
success.
I,
unfortunately,
wasn't
able
to
go,
but
I
think
that
I
think
you're
onto
something
with
that.
So
I'd
be
Keen
to
help
assist
you
with
with
that
type
of
thing.
A
Yeah-
and
it
is
part
of
the
mission
of
the
positioning
group
for
stuff
like
that,
so
you
know
obviously
there's
other
folks
that
would
be
interested
to
help
with
that
and
and
I
think
most
people
in
salsa
are
are
very
much
wanting
to
go
out
and
evangelize
salsa
in
any
way
she
performed,
and
they
definitely
go
out
to
different
conferences,
to
talk
about
salsa
and
how,
to
you
know,
be
salsa
level,
three
compliant
and
et
cetera,
et
cetera,
so
I
I
think
you're
not
going
to
have
issues
getting
people
to
to
join
in
on
this
idea.
A
It's
just
a
matter
of,
like
you
said
the
prioritization
right
and
and
how
we
we
get
there.
E
A
Yeah
so
I
think
this
is
a
great
Forum
I
think
we
need
to
revisit
this
in
the
next
meeting
kind
of
like
what
I
mentioned
earlier
for
the
roadmap,
because
I
think
the
broader
Community
all
the
Sig
leads,
which
aren't
here
today,
I'm
the
only
one
we
we
have
to
I
think
come
to
an
agreement
right
that
this
is
what
we
want
to
do
and
so
I
think
we
revisit
this,
but
I
think
again
we're
not
going
to
have
an
issue
with
people
saying
yes
to
this,
and
then
we
would
probably
do
most
of
the
planning
in
the
positioning
group.
E
B
C
A
No
okay,
I,
don't
see
her
on
any
other
agenda
items.
Questions
comments
that
haven't
been
listed.
Well,
we
we
definitely
have
time,
but
if
there
are
none,
then
we
can
also
end
the
call
early.