On Wed, Sep 30, 2026, 10:43 Alin Jerpelea <[email protected]> wrote:

> Hi,
>
> I am concerned about having HALS outside ASF because they can constitute a
> supply chain attack vector while
>  the lack of central user management can create friction between NuttX
> committers and vendor representatives
>
> I propose that we host the HALS under ASF in a separate repository
> nuttx-vendor-hals with same access and rules
> as we have for the whole project.
>
> This ensures that we have proper oversight, access management and security
> from ASF
>
> Best regards
> Alin
>


+1 for Alin idea to have HAL under Apache license and umbrella in order to
keep coherent and secure SBOM.. which is serious issue if you look how many
malware showed up in the npm js or even pip python packages recently.

HAL/SDK is the problem on its own. If we are looking for a solution let it
be correct right from start.

--
CeDeROM, SQ7MHZ, http://www.tomek.cedro.info

Reply via email to