Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion docs/reference/SSDF-Request-Response.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ We recognize that, according to recent regulations, federal agencies such as you

FOSS is the foundation for essentially all modern software development. Nearly every software product on the market depends on FOSS frameworks, libraries, applications, and compilers. And in this way, community-developed FOSS finds its way into the supply chain of many federal agencies.

We presume that PSF software was obtained by your agency or its suppliers from a publicly available source. According to OMB Memorandum M-23-16, Update to Memorandum M-22-18, [Enhancing the Security of the Software Supply Chain through Secure Software Development Practices](https://www.whitehouse.gov/wp-content/uploads/2023/06/M-23-16-Update-to-M-22-18-Enhancing-Software-Security-1.pdf), federal agencies are not required to collect attestations from the producers of either (1) “third-party software components that are incorporated into the software end product used by the agency,” or (2) “open-source software freely and directly obtained by Federal agencies.”
We presume that PSF software was obtained by your agency or its suppliers from a publicly available source. According to OMB Memorandum M-23-16, Update to Memorandum M-22-18, [Enhancing the Security of the Software Supply Chain through Secure Software Development Practices](https://www.whitehouse.gov/wp-content/uploads/2023/06/M-23-16-Update-to-M-22-18-Enhancing-Software-Security.pdf), federal agencies are not required to collect attestations from the producers of either (1) “third-party software components that are incorporated into the software end product used by the agency,” or (2) “open-source software freely and directly obtained by Federal agencies.”

Therefore, our understanding is that your agency does not require an attestation from PSF. We trust this resolves the matter. If you have any questions about our position, you may contact our [TITLE] [NAME] at [CONTACT INFO].

Expand Down