RFC process
Proposed - coming soon
This RFC process is a proposed model and not yet in operation. Formal governance is being established; today the project is developed in the open on GitHub.
OSDF evolves through an open Request for Comments process. Substantive changes to the format, schemas, profiles, or cryptographic suites require an accepted RFC.
Lifecycle
text
Draft → Proposed → Review → Last Call → Accepted → Implemented ↘ Rejected / WithdrawnWhen an RFC is required
- New or changed manifest, schema, or container rules
- New profiles or changes to profile requirements
- Algorithm additions, deprecations, or default changes
- Anything affecting an interoperability or security guarantee
Anatomy of an RFC
| Section | Purpose |
|---|---|
| Summary | One paragraph: what and why |
| Motivation | Problem and use cases |
| Specification | Normative, testable changes |
| Security & privacy | Impact analysis |
| Compatibility | Migration and versioning |
| Test vectors | Required for acceptance |
Acceptance
An RFC is accepted by the Technical Steering Committee after Last Call, once it has at least two independent implementation commitments and an accompanying set of test vectors.