Slide 10
Slide 10 text
If you liked it, you shoulda put an Org on it
Software supply chain assurance is a real concern in an enterprise
● Challenges with random open repos
○ How well reviewed is the provenance of the code we’re bringing in?
○ If it’s a one-person show, external pull requests may or may not be tightly
reviewed
● Health of a project
○ Look at the commit history
○ Look at the mailing lists
○ What is the activity level of the project?
○ Is it still actively supported?
● And of course incubating through a foundation is helpful
○ LocationTech, OSGeo, Apache, etc.