Hi ASF Community Development team,

I am reaching out from the OpenChain CRA Working Group regarding the
OpenChain CRA Checklist:

https://github.com/OpenChain-Project/CRA-Compliance/blob/main/CRA_Checklist_Requirement_latest.md

Given the Apache Software Foundation’s important role in open source
governance, licensing, release practices, security guidance, and
vulnerability handling, I wanted to ask whether this would be appropriate
to discuss or reference publicly within the ASF community.

This is not a request for formal endorsement or adoption. I understand that
Apache projects are independently governed, so this could simply be framed
as a community resource that may help projects, users, or downstream
adopters think about CRA readiness mapping.

A public mailing-list discussion, community note, project-level reference,
blog post, or documentation mention saying that the checklist may be useful
for CRA readiness mapping would already be very helpful.

If such a public reference is available, we would like to cross-reference
it in Annex D of the OpenChain CRA materials. If this is not the right ASF
list for this question, I would be grateful if you could point me to the
appropriate public list or contact.

Thank you,
Devashri Datta
Chair, OpenChain CRA Working Group
Linux Foundation

Reply via email to