-
Notifications
You must be signed in to change notification settings - Fork 83
Add Q2 2026 BEAR WG report #611
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,132 @@ | ||
| # 2026 Q2 BEAR WG | ||
|
|
||
| [Q1 2026 TAC report](https://github.com/ossf/tac/blob/main/TI-reports/2026/2026-Q1-BEAR-WG.md) | ||
|
|
||
| ## Overview | ||
|
|
||
| The BEAR WG continues our mission to increase representation and strengthen the overall effectiveness of the cybersecurity workforce. The WG continues to see relatively low regular attendance in meetings (5 attendees on avg), we are seeing increased engagement on Slack. | ||
|
|
||
| Over the past quarter, we've made progress in these areas: | ||
|
|
||
| * We hosted one Welcome Call - BEAR WG on March 26. | ||
| * Summer 2026 Mentorship Program has been the main focus of this quarter so far: | ||
| * Received a total of 270+ applications for the 4 participating projects | ||
| * Acceptances to 8 mentees were sent on May 1 | ||
| * Preparing two presentations on the BEAR WG at OSS NA and OpenSSF Community Day keynote. | ||
| * Hosting a lunch meetup on Wednesday after our OSSNA talk. | ||
| * OSSAfrica represented the SIG’s work and OpenSSF at the AfricaCyberFest with a booth managed by Ejiro, Ijeoma, and Harmony, as well as Ejiro’s talk about the state of OSS in Africa. | ||
|
|
||
| ## Welcome Calls | ||
|
|
||
| ### Purpose | ||
|
|
||
| Our Welcome Calls are a monthly event in which we highlight maintainers and/or contributors from OpenSSF Projects or working groups to talk about their initiative. The goal is to allow for information sharing for new members to understand the initiative, current efforts, where the TI needs help, and how to connect. Each month, we aim to host diverse TIs to help spread the awareness of OpenSSF WGs and Projects. | ||
|
|
||
| ### Current Status | ||
|
|
||
| We hosted a third Welcome Call in March featuring the BEAR WG. Since, we have unfortunately been unable to engage with other working groups interested in participating in the Welcome Calls, as well as the calls conflicting with conference dates. We are canceling our May Welcome call. | ||
|
|
||
| ### Up Next | ||
|
|
||
| Find willing working groups to participate in the upcoming June and July Welcome Calls. For August, we are working with Sal and Ejiro to run the Mentorship Showcase as our welcome call. | ||
|
|
||
| ## OpenSSF Mentorship Program | ||
|
|
||
| ### Purpose | ||
|
|
||
| Hands-on experience and contributions to OSS projects are a major advantage for obtaining a job in SWE and/or cybersecurity. At the same time, mentoring and coaching experiences are increasingly viewed as important leadership skills in tech jobs. The OpenSSF Mentorship Program (via LFX) offers these experiences and opportunities to students and individuals from underrepresented groups to boost the skills they need to enter the cybersecurity workforce, and to OpenSSF project maintainers wishing to grow their community by mentoring rising developers. | ||
|
|
||
| ### Current Status | ||
|
|
||
| * Acceptances to 8 mentees were sent May 1: | ||
| * gittuf: 2 | ||
| * RSTUF: 3 | ||
| * Minder: 1 | ||
| * SBOMit: 2 | ||
| * Mentees will be onboarding until June 1 | ||
|
|
||
| ### Up Next | ||
|
|
||
| * Mentorship to run June 1-August 21 (12 weeks) | ||
| * Ejiro Oghenekome and Sal Kimmich to step in as interim co-chairs July-August 2026. | ||
| * Mentees will showcase their projects during the August Welcome Call (coordinated by Sal and Ejiro) | ||
| * Kate and Yesenia will follow up while Marcela is out June-August. | ||
| * Kate will support once Yesenia is out in August. | ||
|
|
||
| ## Conference Participation | ||
|
|
||
| ### Purpose | ||
|
|
||
| Members of the OpenSSF BEAR WG community present talks and panel discussions at major industry conferences to raise awareness about the WG and to engage with folks beyond the OpenSSF. A primary goal of the talks and panels is to share their experiences and advice for newcomers to the OSS and cybersecurity space. | ||
|
|
||
| ### Current Status | ||
|
|
||
| We had two talks accepted at OSS NA and OpenSSF Community Day: | ||
|
|
||
| * OSS NA: BEAR-ing Fruit: How OpenSSF’s Working Group Is Diversifying Open Source Security | ||
| * OpenSSF Community Day Keynote: BEAR-ing Fruit: A Year of Learning, Mentorship, and Community Building in Open Source Security | ||
|
|
||
| In addition, we plan to host a BEAR Lunch Meetup on Wednesday during OSS NA. | ||
|
|
||
| ### Up Next | ||
|
|
||
| Most conference participation for the remainder of the year will flow through the OSSAfrica and DelRev SIGs. We will revisit conferences in the later part of 2026 and early 2027. | ||
|
|
||
| ## OSSAfrica SIG | ||
|
|
||
| ### Purpose | ||
|
|
||
| The SIG is dedicated to fostering collaboration, education, and innovation in open source software and cybersecurity throughout Africa. Our goal is to empower African developers, security professionals, and enthusiasts to contribute to and benefit from the global open source ecosystem. | ||
|
|
||
| ### Current Status | ||
|
|
||
| In the remainder of Q1 2026 and throughout Q2, the SIG: | ||
|
|
||
| * Ramped up social media engagement to increase awareness of OpenSSF technical and non-technical initiatives. | ||
| * Participated in [AfricaCyberFest](https://africacyberfest.com/) on May 2 in Lagos, Nigeria with a talk (Ejiro Oghenekome) and a booth (Ijeoma Onwuka and Harmony Elendu) | ||
| * Hosted a webinar "Advancing Open Source Security in Africa: OpenSSF and OSSAfrica" on March 27 with panelists Abigail Mesrenyame Dogbe, Aaron Will Djaba, Marcela Melara and David Wheeler. Host: Prince Oforh Asiedu | ||
| * Worked on some pre-sandbox projects and have some working prototypes | ||
| * [Skillguard](https://github.com/ossafrica/skillguard): Security Scanner For AI Agent Skills | ||
|
|
||
| ### Up Next | ||
|
|
||
| EDIT 5/14 post-TAC meeting: After internal discussions among the SIG and BEAR WG leadership, and identifying irreconcilable differences, the OSSAfrica initiative has decided to break it's affiliation with OpenSSF towards establishing an independent organization. The BEAR WG does remain committed to supporting the growing OSS/cybersecurity community across Africa, so the WG is in the process of establishing a separate OpenSSF Africa SIG within the WG. The WG co-chairs wish the OSSAfrica group leads all the best in the next chapter of their initiative! | ||
|
|
||
| ## DevRel SIG | ||
|
|
||
| ### Purpose | ||
|
|
||
| * Demonstrate the value proposition of making developer's lives easier and reduce perceived workload of OpenSSF | ||
| * Increase community engagement with OpenSSF Technical Initiatives and Events. | ||
| * Increase awareness and visibility of OpenSSF, its projects, tools, initiatives. | ||
| * Increase non-member contributions / participation | ||
| * Increase adoption | ||
|
|
||
| ### Current Status | ||
|
|
||
| * Two DevRel community sessions accepted at Open Source Summit NA / cdCon (May 18–20, Minneapolis) — see Up Next for details | ||
| * Work underway to build CFP support and speaker resources so Ambassadors and other community members can effectively represent OpenSSF technical initiatives at external events. | ||
|
|
||
| ### Up Next | ||
|
|
||
| * DevRel community meeting May 14 11:30am ET | ||
| * Two sessions from DevRel community members (Katherine Druckman (JetBrains), Stacey Potter (OpenSSF), Tabatha DiDomenico (G-Research), Kadi McKean (ReversingLabs)) at cdCon (May 18–20, Minneapolis), both Room 200C, Tuesday May 19: | ||
| * Bring Your Lunch, We'll Bring Our Notebooks: Securing Software Workflows — 12:45pm CDT — Open-floor feedback session with project maintainers in the room — no slides, no pitches. | ||
| * Security Things: How OpenSSF's Technical Initiatives Keep You Safe From the Upside Down! — 2:10pm CDT — Real supply chain problems mapped to OpenSSF solutions, with lightning-round demos from Working Group Leads and Project Maintainers. | ||
|
|
||
| ## Funding requests and updates | ||
|
|
||
| The [LFX Mentorship (summer cycle ‘26)\]([https://github.com/ossf/tac/issues/573](https://github.com/ossf/tac/issues/573)) request has been closed upon the acceptance of 8 summer mentees. Mentees will be paid in two installments following successful 6-week and final 12-week reviews. | ||
|
|
||
| No new requests at this time. | ||
|
|
||
| ## Questions/Issues for the TAC | ||
|
|
||
| * Welcome Calls: We have been struggling to get responses from other WGs willing to host a Welcome Call. Would love the TAC’s help in promoting these as part of our more general community onboarding resources. | ||
| * OSSAfrica SIG would like to host software projects (TAC process for SIG-sponsored projects isn’t 100% clear) — should the SIG follow the regular Project Sandbox process? | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Is it too much of a burden for a SIG to have their WG own this?
Contributor
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. At least in the context of OSSAfrica, I think this just became a moot point, since the group has decided to leave OpenSSF. |
||
|
|
||
| ## Additional Information | ||
|
|
||
| * Reminder: Marcela is planning to go on 12-week parental leave on/about the first week of June. | ||
| * Reminder: Yesenia is planning to go on parental leave on/about the beginning of August. More details to follow. | ||
| * There will be about a 3 meeting gap between Yesenia leaving and Marcela returning. Our idea is to cancel the BEAR WG calls until Marcela returns with Ejiro Oghenekome and Sal Kimmich serving as interim co-chairs to support the August Mentorship Showcase. | ||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I think the quarterly TAC reviews would be a good opportunity for us to advertise this and incite TIs to sign up for it.