<div dir="auto">The ossf claims to have one, but it is not so helpful.<div dir="auto"><a href="https://best.openssf.org/Concise-Guide-for-Evaluating-Open-Source-Software" target="_blank" rel="noreferrer">https://best.openssf.org/Concise-Guide-for-Evaluating-Open-Source-Software</a></div><div dir="auto"><br></div><div dir="auto">I would start with a short list based on Biden's EO and expand as we move forward </div><div dir="auto">1. Is there an accountable party to address vulnerabilities?</div><div dir="auto">2. Is there a comprehensive SBOM.</div><div dir="auto"><br></div><div dir="auto"><br><br><div data-smartmail="gmail_signature" dir="auto">thx ..Tom (mobile)</div></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Fri, Sep 8, 2023, 12:45 AM <<a href="mailto:torsten@lodderstedt.net" target="_blank" rel="noreferrer">torsten@lodderstedt.net</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div>
<div name="messageBodySection">
<div dir="auto">Hi Tom, <br>
<br>
good idea. Is there a concise list of those requirements? <br>
<br>
best regards,<br>
Torsten. </div>
</div>
<div name="messageReplySection">Am 5. Sept. 2023, 21:37 +0200 schrieb Tom Jones via Openid-specs-ab <<a href="mailto:openid-specs-ab@lists.openid.net" rel="noreferrer noreferrer" target="_blank">openid-specs-ab@lists.openid.net</a>>:<br>
<blockquote type="cite" style="border-left-color:grey;border-left-width:thin;border-left-style:solid;margin:5px 5px;padding-left:10px">
<div dir="auto">Based on the DHS requirements I believe we will need to put into place security requirements for oss libraries if we want to see any government adoption. We may as well start now!<br>
<br>
<div data-smartmail="gmail_signature">thx ..Tom (mobile)</div>
</div>
<br>
<div class="gmail_quote">
<div dir="ltr" class="gmail_attr">On Tue, Sep 5, 2023, 10:38 AM Kristina Yasuda via Openid-specs-ab <<a href="mailto:openid-specs-ab@lists.openid.net" rel="noreferrer noreferrer" target="_blank">openid-specs-ab@lists.openid.net</a>> wrote:<br></div>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div lang="EN-US" link="#467886" vlink="#96607D" style="word-wrap:break-word">
<div>
<p class="MsoNormal">Hi,<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">Following are the open source libraries that the DCP WG co-chairs are aware of for the OID4VC specification family. Please let us know if we are missing any! This is important for keeping up to date our presentations, WG page and identifying potential participants of OID4VC test suite that OIDF certification team has been making a lot of progress on!<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">Walt.id <u></u><u></u></p>
<ul style="margin-top:0in" type="disc">
<li style="margin-left:0in"><a href="https://github.com/walt-id/waltid-ssikit" rel="noreferrer noreferrer noreferrer" target="_blank">https://github.com/walt-id/waltid-ssikit</a> (Kotlin)<u></u><u></u></li>
</ul>
<p class="MsoNormal">Sphereon <u></u><u></u></p>
<ul style="margin-top:0in" type="disc">
<li style="margin-left:0in"><a href="https://github.com/Sphereon-Opensource/SIOP-OpenID4VP" rel="noreferrer noreferrer noreferrer" target="_blank">https://github.com/Sphereon-Opensource/SIOP-OpenID4VP</a> (Typescript)<u></u><u></u></li>
<li style="margin-left:0in"><a href="https://github.com/Sphereon-Opensource/OpenID4VCI-client" rel="noreferrer noreferrer noreferrer" target="_blank">https://github.com/Sphereon-Opensource/OpenID4VCI-client</a> (Typescript)<u></u><u></u></li>
<li style="margin-left:0in"><a href="https://github.com/Sphereon-Opensource/ssi-sdk" rel="noreferrer noreferrer noreferrer" target="_blank">https://github.com/Sphereon-Opensource/ssi-sdk</a> (Typescript)<u></u><u></u></li>
</ul>
<p class="MsoNormal">Microsoft<u></u><u></u></p>
<ul style="margin-top:0in" type="disc">
<li style="margin-left:0in"><a href="https://github.com/microsoft/VerifiableCredential-SDK-Android" rel="noreferrer noreferrer noreferrer" target="_blank">https://github.com/microsoft/VerifiableCredential-SDK-Android</a> (Kotlin)<u></u><u></u></li>
<li style="margin-left:0in"><a href="https://github.com/microsoft/VerifiableCredential-SDK-iOS" rel="noreferrer noreferrer noreferrer" target="_blank">https://github.com/microsoft/VerifiableCredential-SDK-iOS</a> (Swift)<u></u><u></u></li>
</ul>
<p class="MsoNormal">Spruce <u></u><u></u></p>
<ul style="margin-top:0in" type="disc">
<li style="margin-left:0in"><a href="https://github.com/spruceid/oidc4vci-rs" rel="noreferrer noreferrer noreferrer" target="_blank">https://github.com/spruceid/oidc4vci-rs</a> (Rust)<u></u><u></u></li>
<li style="margin-left:0in"><a href="https://github.com/spruceid/oidc4vci-issuer" rel="noreferrer noreferrer noreferrer" target="_blank">https://github.com/spruceid/oidc4vci-issuer</a> (Rust)<u></u><u></u></li>
</ul>
<p class="MsoNormal">EBSI<u></u><u></u></p>
<ul style="margin-top:0in" type="disc">
<li style="margin-left:0in"><a href="https://api-pilot.ebsi.eu/docs/libraries" rel="noreferrer noreferrer noreferrer" target="_blank">https://api-pilot.ebsi.eu/docs/libraries</a> (Javascript)<u></u><u></u></li>
</ul>
<p class="MsoNormal">Impierce Technologies<u></u><u></u></p>
<ul style="margin-top:0in" type="disc">
<li style="margin-left:0in"><a href="https://github.com/impierce/openid4vc" rel="noreferrer noreferrer noreferrer" target="_blank">https://github.com/impierce/openid4vc</a> (Rust)<u></u><u></u></li>
</ul>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">Cheers,<u></u><u></u></p>
<p class="MsoNormal">Kristina<u></u><u></u></p>
</div>
</div>
_______________________________________________<br>
Openid-specs-ab mailing list<br>
<a href="mailto:Openid-specs-ab@lists.openid.net" rel="noreferrer noreferrer noreferrer" target="_blank">Openid-specs-ab@lists.openid.net</a><br>
<a href="https://lists.openid.net/mailman/listinfo/openid-specs-ab" rel="noreferrer noreferrer noreferrer noreferrer" target="_blank">https://lists.openid.net/mailman/listinfo/openid-specs-ab</a><br></blockquote>
</div>
_______________________________________________<br>
Openid-specs-ab mailing list<br>
<a href="mailto:Openid-specs-ab@lists.openid.net" rel="noreferrer noreferrer" target="_blank">Openid-specs-ab@lists.openid.net</a><br>
<a href="https://lists.openid.net/mailman/listinfo/openid-specs-ab" rel="noreferrer noreferrer" target="_blank">https://lists.openid.net/mailman/listinfo/openid-specs-ab</a><br></blockquote>
</div>
</div>
</blockquote></div>