►
From YouTube: SLSA Positioning Meeting (December 13, 2022)
Description
Meeting notes: https://docs.google.com/document/d/1tpPOXVzNSwtpWA7cXhTPLAO6HIP50obUvoP85XqgVHM/edit#heading=h.yfiy9b23vayj
SLSA repo: https://github.com/slsa-framework/slsa
B
Hey
Jay
thanks
for
joining
I,
see
Jeff
joining.
Let
me
share
a
screen.
A
B
B
If
you
could
sign
in,
you
can
hear
me
right,
yep,
okay,
awesome,
I,
don't
have
any
agenda
items
today,
because
there's
going
to
be
two
meetings
coming
up
the
supply
chain,
Integrity
one
tomorrow
and
then
the
salsa
one,
and
we
need
to
talk
to
them
about
some
of
this
stuff
yeah.
B
So
I'm,
not
sure
if
you
all
had
topics
to
discuss.
B
If
you
wanted
to
discuss
I,
don't
know
a
strategy
for
next
year.
Etc,
but
I
I
personally,
do
not
have
anything
for
today.
D
No
me
neither
I
I
was
hoping
that
we'd
I
mean
the
means
fall
when
they
fall,
but
we're
getting
a
little
long
in
tooth
in
the
month.
B
Correct
correct,
yeah
and
I
was
thinking
that
I
would
work
on
something
but
again
because
we
haven't
had
those
meetings
yet
with
the
broader
team,
there's
not
really
much
to
work
on
other
than
that
one
blog
to
tweak
up
right,
so
yeah
I,
don't
have
anything
in
particular.
B
So
I
guess
let
me
ask
you
a
question
because
it
could
be
just
Just.
Me,
Myself
and
I
I
feel,
like
I,
have
partly
to
blame
not
been
as
productive
as
we
could
have
been
given
like
all
the
canceled
sessions
Etc,
and
given
that
obviously
I
don't
dedicate
a
lot
of
time
to
this
so
trying
to
get
a
feel
from
the
group
on
you
know:
how
can
we
improve
next
year?
B
How
can
we
get
more
deliverables
out?
You
know,
given
the
the
small
size
of
the
of
the
team
and
obviously
waiting
for
the
specification
to
be
Unleashed
right.
D
Dare
I
say
a
shorter
shot?
Well,
a
a
smaller
Target
with
maybe
a.
D
A
D
D
A
lot
of
what
we
do
here
is
largely
depending
on
the
variables
that
happen
in
the
specification
team,
not
necessarily
the
tooling
team,
but
we
don't
always
know
in
real
time
what
one
hand
is
doing
or
how
the
head
is
thinking
about
how
the
head
is
thinking
whether
or
not
the
hand
that's
moving
is
moving
according
to
the
way
that
the
head
is
thinking
and
then
here
we
are
supposed
to
be
trying
to
provide
that
broader
context
to
the
masses
based
on
trajectory
that
we
don't
really
understand.
D
Like
friends,
I'll
give
you
an
example
of
it,
we're
writing
a
positioning
doc.
At
the
same
time,
they
made
a
decision
to
break
off
source
and
build
oh
by
the
way,
they've
also
broken
off
Providence.
Now
yep
right
with
that,
that's
like
we!
How?
How
are
we
like?
Let's,
let's
say
we
got
that
done
fast-
it
would
have
been
wrong.
B
So
so
then
the
question
is:
how
do
we
get
ahead
of
that
and
I'm
guessing?
D
Yeah,
the
the
part
that
the
part
that
I
said
I
don't
know
that
it
that
it
so
the
part,
that's
that
will
conflict
with
this
right,
it'll
be
a
competing
priority
thing.
Do
we
tell
them
to
slow
down
right,
I
mean
it's
like
you
don't
be
like
hey
hold
on
a
second.
Let
us
get
that
part
out
before
we
can
do
you
know
or
or
do
we
or
do
we
base
what
we
do
on
forecasting
right
so
so
is.
It
is
the
way
that
we
position
now
something
that's
future
State,
rather
than
current.
B
C
I
I
I've
kind
of
echo
a
lot
of
what
Jay
said.
Obviously
what
what
we
do
here
is
is
depend
on
on
the
larger
group,
but
I
do
think
that
we
we
got
really
excited
at
the
very
beginning
and
took
on
tons
of
stuff
I.
I
know
I
did
personally
and
then
mostly
because
we
all
have
day
jobs.
C
C
A
B
So
what
do
you
think
those
smaller
objectives
look
like
for
next
year
right?
We
had
thoughts
on
you
know
some
blogs,
which
obviously
we
we
are
having
some
headwinds
on
because
of
the
variableness
of
the
specification.
D
Yeah,
that's
what
I
meant
by
a
smaller
Target
right
like
like
we,
we
small
a
target
with
a
with
an
even
smaller
shock
group
right.
You
know
one
thing
at
a
time
focusing
on
that
and
then
yeah
that
that
that's
a
that's
a
huge,
huge
plus
one
for
me,
I
mean
at
least
that
way
and
and
then,
if
we
we
did
that
and
then
I
I
guess
I
said
focused
on
on
future
State
stuff
right.
D
But
if
we,
if
we
did
that
and
then
made
it
above
a
future
state,
it
might
be
something
that
we
can
that
we
can
dig
into,
and
it
still
has
relevance
like
a
like
a
couple
of
weeks
from
now,
rather
than
we
dig
into
it,
and
then
we
look
up
and
then
like
well,
we
did
a
whole
bunch
of
work
yep
for
almost
nothing.
You
know,
I
mean.
B
The
development
blog
right
was
a
smaller
Target
in
in
my
view,
so
how
do
we
make
that
even
smaller.
D
We
really
got
our
our
Minds
Twisted
when
we
look
back
at
the
spec
as
it
was
from
when
we
started
it
and
to
when
we
were
working
on
the
in
the
middle
and
we
look
back
at
the
spec
and
we
saw
the
split
that
really
and
and
then
when
we
saw
the
split
and
then
and
then
the
fact
that
the
split
didn't
take
hold
across
all
of
the
the
different
media,
Outlets
or
different
Outlets,
that
were
the
blogs
that
were
being
used
across
the
Spectrum.
Then
there
was
confusion,
I.
D
The
the
big,
the
the
big
that
the
head
got
a
little
ahead
of
itself
and
that
really
that
really
drove
a
drove
away.
We
had
we
asked
questions
that
required
answers
that
weren't
really
like
for,
like,
for
instance,
right
now.
We
asked
questions
that
require
answers,
that
we
still
have
to
wait
to
get
I.
Think
I,
think
you
you,
you
know
having
having
the
the
the
other
Sig
leads
attend.
D
A
D
Know
just
or
at
least
a
representative
right,
maybe
it
doesn't
have
to
be
the
the
leads.
Maybe
it
could
be
a
representative
I
I
either
way
us
having
being
able
to
ask
a
question
real
time
or
or
or
that
or
the
whatever
the
the
answer
might
be,
or
whatever
you
know
whatever
that
variable
or
parameter
is
we're
able
to
address
it
right
then,
and
there,
rather
than
having
to
go
back
based
on
something
we
see
to
get
something
clarified
before
we
can
before
we
can
push
on
yeah.
B
Yeah
we
could
potentially
even
revisit
the
schedule.
I
know
there
were
some
assumptions
made
at
the
beginning
when
we
were
figuring
out
the
schedule
for
this
call
that
they
wanted
certain
people
to
be
part
of
this
call,
but
they've
only
ever
attended
to
meetings
at
the
beginning,
and
so
that
shifted
what
actually
the
majority
was.
So
potentially
we
need
to
revisit
also
the
schedule
so
that
other
people
could
potentially
join
from
the
other
six
I
know.
B
Mike
does
a
good
job
and
I
know
he's
been
on
conferences
and
things
like
that,
and
he
said
he
was
going
to
step
away
for
a
little
while
right.
So
that's
an
example
of
the
tooling
thing
right.
He
he
holds
that,
but
for
the
specification,
Mike
is
the
closest
thing,
but
he's
not
necessarily
a
lead
right,
so
it'd
be
good
to
get
Josh
Orr
mark
because
they're
driving
a
lot
of
the
background
stuff.
Well.
D
So
that
that's
what
I
was
going
to
say
too,
they
have
to
be
somebody.
That's
that's
not
that's!
On
the
the
the
ugly
well
I
say
internal
internal
to
to
to
them
external
to
us
right.
Somebody
on
the
side
where
some
of
the
conversations
are
happening
off.
You
know
off
mic.
I
guess
you
know,
they'd
have
to
be
privy
to
a
lot
of
that
stuff
too.
B
Yeah
correct
and
that's
where
I
think
the
the
two
leads
come
in
for
specification
at
the
very
least
I
know:
Mark
drives
a
lot
of
it.
Yeah
and
I
know
there's
other
Google
employees
that
also
drive
a
lot
of
it
behind
the
scenes
and
then
I
know
Josh
is
at
the
VMware
side
and
I'm
sure
he
has
conversations
with
Mark
all
the
time,
so
either
one
of
those
I
think
would
be
more
clued
in
I.
B
Think
then
the
majority
just
because
of
the
nature
of
how
they're
going
about
the
work
and
they're
drafting
up
documents
left
and
right
prior
to
the
meeting.
You
know
after
the
meeting
Etc
et
cetera.
A
D
I'd
like
to
I'd
like
to
I,
guess
we
can
get
this
tomorrow
or
it
does.
Is
it
tomorrow
that
the
next
meetings
are
is.
D
Yeah
I'd
like
to
get
so
I
I'll
wait
for
the
sauce
meeting
and
I
may
or
may
not
be
able
to
attend
that
one
I
might
have
to
be
on
the
flight.
I
gotta
be
on
the
flight
at
some
point.
During
the.
D
To
get
to
that
one,
let
me
see
a
place
not
in
school
12
right,
so
I
might
be.
I
may
be
able
to
attend
that
one.
What
I'd
like
to
know
is
for
us.
D
What
is
what
are,
are
the
the
Boulder
size
items
that
that
we
want
to
get
accomplished
for
next
year,
or
maybe
we
can
just
as
an
Outlook,
take
our
cues
or
build
some
type
of
a
road
map
based
on
that,
maybe
we
can
get
ahead
of
a
few
things.
B
Okay,
I,
don't
see
an
agenda
for
that
I
know
they
like
to
cancel
the
meeting
if
there's
not
an
agenda
before
the
meeting
which
I'm
not
a
fan
of.
So
let
me
this:
is
it
right
supply
chain,
integrity.
B
Yeah
but
I
I
do
know
that
they've
canceled
it
in
the
past
when
there's
no
agenda
items
yeah.
So
instead
of
this
is
December
14th,
okay,
agenda.
B
B
B
D
Yeah
yeah
that
there's
got
to
be
there's
got
to
be
better.
The
the
communication
and
crosstalk
has
got
to
be
a
little
bit
better.
B
That
yeah
and
then.
D
B
D
Matter
of
fact,
just
they're
just
talking
about
that
attack
meeting
this
morning
about
better
Synergy
between
all
of
the
you
know
between
the
some
of
these
offshoot
projects
and
then
what
some
of
the
working
groups
are
doing.
D
You
know
every
the
working
group
said
that
we're
doing
all
great
stuff,
but
you
know
some
of
this
stuff
is,
can
be
blunt
to
can
be
Blended
together
or
find
ways
to
to
mix
things,
but
you
know
bring
things
together
or
work
a
little
bit
more
collaboratively
across
the
spectrum
of
what
we
do
in
the
open
ssf
which,
which
is
you
know,
I
mean
that
that's
a
must
at
this
point.
B
Approximate
time
I
don't
know,
I
feel
like
this
is
going
to
be
like
a
a
can
of
worms.
These
two
well.
D
B
You
have
to
be
aligned
at
some
level
with
each
other
Okay.
So
I
will
put
that
on
the
agenda
for
tomorrow
and
then
I
feel
like
maybe
it's
the
same
thing
for
salsa
too
right
yeah.
It's
the
same
questions.
Ultimately,
what
is
this
occurring
critical
projects?
Okay,.
A
D
Avoid
it
I
really
feel
like
well,
because
securing
so
this
you
really
can't
avoid
it,
but
I
feel
like
sometimes
they
need
to
space.
These.
Damn
things
out,
give
people
a
chance
to
yeah.
B
Yeah
I
I
I
agree
I'm,
trying
to
click
on
that
I
want
to.
Let
me
click
on
it.
That's
weird!
You
see
what
it's
doing.
If
I
try
to
click
on
it,
it
it
Scrolls
down.
B
I
just
want
to
click
on
this.
This.
B
B
B
Maybe
this
is
just
one
since
it's
not
talking
about
all
three
groups:
yeah,
okay,
there,
okay,
at
least
we
we
have
those
two
and
then
there
was
this
other
one.
The
this
one.
B
Think
that
was
that
was
it
right:
yeah
yeah
I
think
that
was
it
okay
I've
at
least
copied
those
down
for
the
two
meetings.
Anything
else.
B
B
Yeah
there
is
so
depending
on
what
happens
right
might
start
getting
working
on
on
the
other
stuff.
So
if
you're
all
are
here,
I'll
see
you
next
week.
If
not,
then
I'll
see
you
next
year,
okay,
going
once
going
twice:
okay!
Well
thanks
everyone
for
joining,
and
hopefully
we
can
get
some
answers
from
the
larger
Community
about
how
to
improve
next
year.
Yeah.