Hi ASF Community Development team, I am reaching out from the OpenChain CRA Working Group regarding the OpenChain CRA Checklist:
https://github.com/OpenChain-Project/CRA-Compliance/blob/main/CRA_Checklist_Requirement_latest.md Given the Apache Software Foundation’s important role in open source governance, licensing, release practices, security guidance, and vulnerability handling, I wanted to ask whether this would be appropriate to discuss or reference publicly within the ASF community. This is not a request for formal endorsement or adoption. I understand that Apache projects are independently governed, so this could simply be framed as a community resource that may help projects, users, or downstream adopters think about CRA readiness mapping. A public mailing-list discussion, community note, project-level reference, blog post, or documentation mention saying that the checklist may be useful for CRA readiness mapping would already be very helpful. If such a public reference is available, we would like to cross-reference it in Annex D of the OpenChain CRA materials. If this is not the right ASF list for this question, I would be grateful if you could point me to the appropriate public list or contact. Thank you, Devashri Datta Chair, OpenChain CRA Working Group Linux Foundation
